DocumentCode :
3100783
Title :
HIMA: A Hypervisor-Based Integrity Measurement Agent
Author :
Azab, Ahmed M. ; Ning, Peng ; Sezer, Emre C. ; Zhang, Xiaolan
Author_Institution :
North Carolina State Univ., Raleigh, NC, USA
fYear :
2009
fDate :
7-11 Dec. 2009
Firstpage :
461
Lastpage :
470
Abstract :
Integrity measurement is a key issue in building trust in distributed systems. A good solution to integrity measurement has to provide both strong isolation between the measurement agent and the measurement target and time of check to time of use (TOCTTOU) consistency (i.e., the consistency between measured version and executed version throughout the lifetime of the target). Unfortunately, none of the previous approaches provide (or can be easily modified to provide) both capabilities. This paper presents HIMA, a hypervisor-based agent that measures the integrity of virtual machines (VMs) running on top of the hypervisor, which provides both capabilities identified above. HIMA performs two complementary tasks: (1) active monitoring of critical guest events and (2) guest memory protection. The former guarantees that the integrity measures are refreshed whenever the guest VM memory layout changes (e.g., upon creation of processes), while the latter ensures that integrity measurement of user programs cannot be bypassed without HIMA´s knowledge. This paper also reports the experimental evaluation of a HIMA prototype using both micro-benchmark and application benchmark; the experimental results indicate that HIMA is a practical solution for real world applications.
Keywords :
distributed processing; security of data; software agents; virtual machines; VM memory layout; distributed systems; guest memory protection; hypervisor-based integrity measurement agent; virtual machines; Application software; Kernel; Memory management; Protection; Runtime; Time measurement; Virtual machine monitors; Virtual machining; Virtual manufacturing; Voice mail; attestation; integrity measurement; systems security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Security Applications Conference, 2009. ACSAC '09. Annual
Conference_Location :
Honolulu, HI
ISSN :
1063-9527
Print_ISBN :
978-0-7695-3919-5
Type :
conf
DOI :
10.1109/ACSAC.2009.50
Filename :
5380699
Link To Document :
بازگشت