• DocumentCode
    634855
  • Title

    Transparent Security-Sensitive Process Protection via VMM-Based Process Shadowing

  • Author

    Xiaoguang Wang ; Yong Qi ; Yuehua Dai ; Jianbao Ren

  • Author_Institution
    Dept. of Comput. Sci., Xi´an Jiaotong Univ., Xian, China
  • fYear
    2013
  • fDate
    22-26 July 2013
  • Firstpage
    115
  • Lastpage
    120
  • Abstract
    Ensuring the correctness of security sensitive application running on a potentially malicious operating system is an open problem. Existing approaches for protecting a sensitive process are either losing deployment transparency or lack of the inter-process communication ability for the protected process. In this paper, we present a novel approach called shadow process execution (SPE), which can provide security sensitive applications with executing integrity. With the help of virtualization layer, SPE shadows the sensitive application in a separate virtual machine (VM), which significantly removes the complex and potentially malicious software stack from trusted computing base (TCB). At the same time, SPE maintains dynamic runtime protection without application source code. Finally we demonstrate the feasibility of SPE by designing and implementing a prototype system based on KVM hypervisor. And we show the transparent and dynamic feature of SPE by running and protecting a real world encryption utility program.
  • Keywords
    cryptography; operating systems (computers); virtual machines; virtualisation; KVM hypervisor; SPE shadows; VMM based process shadowing; application source code; dynamic runtime protection; interprocess communication ability; malicious operating system; malicious software stack; real world encryption utility program; security sensitive application; shadow process execution; transparent security sensitive process protection; trusted computing base; virtual machine; virtualization layer; Kernel; Linux; Process control; Security; Virtual machine monitors; Virtualization; Application Security; Shadow Process Execution; Transparent and Dynamic Protection; Virtualization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Software and Applications Conference Workshops (COMPSACW), 2013 IEEE 37th Annual
  • Conference_Location
    Japan
  • Type

    conf

  • DOI
    10.1109/COMPSACW.2013.38
  • Filename
    6605775