DocumentCode :
2786102
Title :
Supporting Virtualization-Aware Security Solutions Using a Systematic Approach to Overcome the Semantic Gap
Author :
Ibrahim, Amani S. ; Hamlyn-Harris, James ; Grundy, John ; Almorsy, Mohamed
Author_Institution :
Centre for Comput. & Eng. Software Syst., Swinburne Univ. of Technol., Melbourne, VIC, Australia
fYear :
2012
fDate :
24-29 June 2012
Firstpage :
836
Lastpage :
843
Abstract :
A prerequisite to implementing virtualization-aware security solutions is to solve the "semantic gap" problem. Current approaches require a deep knowledge of the kernel data to manually solve the semantic gap. However, kernel data is very complex; an Operating System (OS) kernel contains thousands of data structures that have direct and indirect (pointer) relations between each other with no explicit integrity constraints. This complexity makes it impractical to use manual methods. In this paper, we present a new solution to systematically and efficiently solve the semantic gap for any OS, without any prior knowledge of the OS. We present: (i) KDD, a tool that systematically builds a precise kernel data definition for any C-based OS such as Windows and Linux. KDD generates this definition by performing points-to analysis on the kernel\´s source code to disambiguate the pointer relations. (ii) SVA, a security appliance that solves the semantic gap based on the generated definition, to systematically and externally map the virtual machines\´ physical memory and extract the runtime dynamic objects. We have implemented prototypes for KDD and SVA, and have performed different experiments to prove their effectiveness.
Keywords :
C language; Linux; data structures; operating system kernels; security of data; virtual machines; virtualisation; C-based OS; KDD tool; Linux; OS kernel; SVA security applicance; Windows; data structure; integrity constraint; kernel data; kernel source code; operating system; pointer relation; points-to analysis; runtime dynamic object; semantic gap problem; systematic approach; virtual machines; virtualization-aware security solution; Algorithm design and analysis; Context; Data structures; Kernel; Runtime; Security; Semantics; IaaS; Kernel data structures; points-to analysis; semantic gap; virtualization-aware security solutions;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Cloud Computing (CLOUD), 2012 IEEE 5th International Conference on
Conference_Location :
Honolulu, HI
ISSN :
2159-6182
Print_ISBN :
978-1-4673-2892-0
Type :
conf
DOI :
10.1109/CLOUD.2012.129
Filename :
6253586
Link To Document :
بازگشت