• DocumentCode
    2530785
  • Title

    NOPFIT: File System Integrity Tool for Virtual Machine Using Multi-byte NOP Injection

  • Author

    Kim, Junghan ; Kim, Inhyuk ; Eom, Young Ik

  • Author_Institution
    Sch. of Inf. & Commun. Eng., Sungkyunkwan Univ., Suwon, South Korea
  • fYear
    2010
  • fDate
    23-26 March 2010
  • Firstpage
    335
  • Lastpage
    338
  • Abstract
    File system integrity is very important to a system security, because it affects all users that share system files. Therefore, file system integrity tool (FIT) is widely used for host based file system monitoring. Recently, virtualization technology is applied to several computing areas such as server virtualization and cloud computing, and increasingly demands for a FIT. However, previous virtual machine FITs are not suitable for virtual machines, because its structure is insufficient to real-time file system monitoring. In this paper, we design and implement a NOPFIT: a FIT using a multi-byte NOP injection on lguest virtual machine. The multi-byte NOP is new debugging technique using undefined opcode exception. Our experimental results demonstrate that the NOPFIT has very low performance overhead. The results indicate that the NOPFIT is appropriate for real-time file system monitoring.
  • Keywords
    file organisation; real-time systems; security of data; virtual machines; NOPFIT; debugging technique; file system integrity tool; host based file system monitoring; lguest virtual machine; multibyte NOP injection; real-time file system monitoring; system security; undefined opcode exception; virtualization technology; Cloud computing; Communication system security; Condition monitoring; File systems; Kernel; Platform virtualization; Real time systems; Software debugging; Virtual machine monitors; Virtual machining; File System Integrity Tool; Realtime System Monitoring; Virtual Machine; lguest;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Science and Its Applications (ICCSA), 2010 International Conference on
  • Conference_Location
    Fukuoka
  • Print_ISBN
    978-0-7695-3999-7
  • Electronic_ISBN
    978-1-4244-6462-3
  • Type

    conf

  • DOI
    10.1109/ICCSA.2010.79
  • Filename
    5476677