DocumentCode :
1890761
Title :
Towards protecting sensitive files in a compromised system
Author :
Zhao, Xin ; Borders, Kevin ; Prakash, Atul
Author_Institution :
Michigan Univ., Ann Arbor, MI
fYear :
2005
fDate :
13-13 Dec. 2005
Lastpage :
28
Abstract :
Protecting sensitive files from a compromised system helps administrators to thwart many attacks, discover intrusion trails, and fast restore the system to a safe state. However, most existing file protection mechanisms can be turned off after an attacker manages to exploit a vulnerability to gain privileged access. In this paper we propose SVFS, a secure virtual file system that uses virtual machine technology to store sensitive files in a virtual machine that is dedicated to providing secure data storage, and run applications in one or more guest virtual machines. Accesses to sensitive files must go through SVFS and are subject to access control policies. Because the access control policies are enforced independently in an isolated virtual machine, intruders cannot bypass file protection by compromising a guest VM. In addition, SVFS introduces a virtual remote procedure call mechanism as a substitute of standard RPC to deliver better performance in data exchanging across virtual machine boundaries. We implemented SVFS and tested it against attacks on a guest operating system using several available rootkits. SVFS was able to prevent most of the rootkits from being installed, and prevent all of them from persisting past reboot. We also compared the performance of SVFS to the native Ext3 file system and found that performance cost was reasonable considering the security benefits of SVFS. Our experimental results also show VRPC does improve the file system performance
Keywords :
authorisation; remote procedure calls; virtual machines; virtual storage; Ext3 file system; access control policy; compromised system; guest operating system; secure data storage; secure virtual file system; sensitive files protection; virtual machine; virtual remote procedure call; Access control; Costs; File systems; Memory; Operating systems; Protection; Security; System testing; Virtual machining; Virtual manufacturing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Security in Storage Workshop, 2005. SISW '05. Third IEEE International
Conference_Location :
San Francisco, CA
Print_ISBN :
0-7695-2537-7
Type :
conf
DOI :
10.1109/SISW.2005.17
Filename :
1628479
Link To Document :
بازگشت