• DocumentCode
    87689
  • Title

    DIV: Dynamic integrity validation framework for detecting compromises on virtual machine based cloud services in real time

  • Author

    Chunlu Wang ; Chuanyi Liu ; Bin Liu ; Yingfei Dong

  • Author_Institution
    Sch. of Comput. Sci., Beijing Univ. of Posts & Telecommun., Beijing, China
  • Volume
    11
  • Issue
    8
  • fYear
    2014
  • fDate
    Aug. 2014
  • Firstpage
    15
  • Lastpage
    27
  • Abstract
    With the increasing popularity of cloud services, attacks on the cloud infrastructure also increase dramatically. Especially, how to monitor the integrity of cloud execution environments is still a difficult task. In this paper, a real-time dynamic integrity validation (DIV) framework is proposed to monitor the integrity of virtual machine based execution environments in the cloud. DIV can detect the integrity of the whole architecture stack from the cloud servers up to the VM OS by extending the current trusted chain into virtual machine´s architecture stack. DIV introduces a trusted third party (TTP) to collect the integrity information and detect remotely the integrity violations on VMs periodically to avoid the heavy involvement of cloud tenants and unnecessary information leakage of the cloud providers. To evaluate the effectiveness and efficiency of DIV framework, a prototype on KVM/QEMU is implemented, and extensive analysis and experimental evaluation are performed. Experimental results show that the DIV can efficiently validate the integrity of files and loaded programs in real-time, with minor performance overhead.
  • Keywords
    cloud computing; trusted computing; virtual machines; DIV framework; TTP; VM OS; cloud infrastructure attacks; cloud providers; cloud tenants; dynamic integrity validation framework; operating systems; trusted third party; virtual machine based cloud services; virtual machine based execution environment; Computer architecture; Hardware; Real-time systems; Security; Servers; Software; Virtual machining; cloud security; cloud trustworthiness; remote attestation; trusted computing;
  • fLanguage
    English
  • Journal_Title
    Communications, China
  • Publisher
    ieee
  • ISSN
    1673-5447
  • Type

    jour

  • DOI
    10.1109/CC.2014.6911084
  • Filename
    6911084