• DocumentCode
    680129
  • Title

    Unobservable intrusion detection based on call traces in paravirtualized systems

  • Author

    Maiero, Carlo ; Miculan, Marino

  • Author_Institution
    Department of Mathematics and Computer Science, University of Udine, Italy
  • fYear
    2011
  • fDate
    18-21 July 2011
  • Firstpage
    300
  • Lastpage
    306
  • Abstract
    We present a non-invasive system for intrusion and anomaly detection, based on system call tracing in paravirtualized machines over Xen. System calls from guest user programs and operating systems are intercepted stealthy within Xen hypervisor, and passed to a detection system running in Dom0 via a suitable communication channel. Guest applications and machines are left unchanged, and an intruder on the virtual machine cannot tell whether the system is under inspection or not. As for the detection algorithm, we present and study a variant of Stide, which we verify experimentally to have a good performance on intrusion detection with an acceptable overhead—in fact, online real-time intrusion detection feasible. However, since the interception mechanism is kept separated from the detection system, the latter can be replaced according to further needs.
  • Keywords
    Computer architecture; Databases; Inspection; Kernel; Monitoring; Ports (Computers); Virtual machine monitors; Intrusion detection systems; Paravirtualization; System call trace analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Cryptography (SECRYPT), 2011 Proceedings of the International Conference on
  • Conference_Location
    Seville, Spain
  • Type

    conf

  • Filename
    6732403