DocumentCode :
2027654
Title :
CloudSec: A security monitoring appliance for Virtual Machines in the IaaS cloud model
Author :
Ibrahim, Amani S. ; Hamlyn-Harris, James ; Grundy, John ; Almorsy, Mohamed
Author_Institution :
Centre for Comput. & Eng. Software Syst., Swinburne Univ. of Technol., Hawthorn, VIC, Australia
fYear :
2011
fDate :
6-8 Sept. 2011
Firstpage :
113
Lastpage :
120
Abstract :
The Infrastructure-as-a-Service (IaaS) cloud computing model has become a compelling computing solution with a proven ability to reduce costs and improve resource efficiency. Virtualization has a key role in supporting the IaaS model. However, virtualization also makes it a target for potent rootkits because of the loss of control problem over the hosted Virtual Machines (VMs). This makes traditional in-guest security solutions, relying on operating system kernel trustworthiness, no longer an effective solution to secure the virtual infrastructure of the IaaS model. In this paper, we explore briefly the security problem of the IaaS cloud computing model, and present CloudSec, a new virtualization-aware monitoring appliance that provides active, transparent and real-time security monitoring for hosted VMs in the IaaS model. CloudSec utilizes virtual machine introspection techniques to provide fine-grained inspection of VM´s physical memory without installing any monitoring code inside the VM. It actively reconstructs and monitors the dynamically changing kernel data structures instances, as a prior step to enable providing protection for kernel data structures. We have implemented a proof-of-concept prototype using VMsafe libraries on a VMware ESX platform. We have evaluated the system monitoring accuracy and the performance overhead of CloudSec.
Keywords :
cloud computing; data structures; operating system kernels; security of data; virtual machines; CloudSec; VM physical memory; VMsafe libraries; VMware ESX platform; fine grained inspection; in-guest security solutions; infrastructure-as-a-service cloud computing model; kernel data structures; operating system kernel trustworthiness; security monitoring appliance; virtual machine introspection techniques; virtualization; virtualization aware monitoring appliance; Data structures; Kernel; Memory management; Monitoring; Security; Semantics; Virtual machine monitors; Cloud Computing; IaaS Security; Semantic Gap; VMsafe APIs; VMware ESX; Virtual Appliance; Virtual Machine Introspection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network and System Security (NSS), 2011 5th International Conference on
Conference_Location :
Milan
Print_ISBN :
978-1-4577-0458-1
Type :
conf
DOI :
10.1109/ICNSS.2011.6059967
Filename :
6059967
Link To Document :
بازگشت