Title :
NOPFIT: File System Integrity Tool for Virtual Machine Using Multi-byte NOP Injection
Author :
Kim, Junghan ; Kim, Inhyuk ; Eom, Young Ik
Author_Institution :
Sch. of Inf. & Commun. Eng., Sungkyunkwan Univ., Suwon, South Korea
Abstract :
File system integrity is very important to a system security, because it affects all users that share system files. Therefore, file system integrity tool (FIT) is widely used for host based file system monitoring. Recently, virtualization technology is applied to several computing areas such as server virtualization and cloud computing, and increasingly demands for a FIT. However, previous virtual machine FITs are not suitable for virtual machines, because its structure is insufficient to real-time file system monitoring. In this paper, we design and implement a NOPFIT: a FIT using a multi-byte NOP injection on lguest virtual machine. The multi-byte NOP is new debugging technique using undefined opcode exception. Our experimental results demonstrate that the NOPFIT has very low performance overhead. The results indicate that the NOPFIT is appropriate for real-time file system monitoring.
Keywords :
file organisation; real-time systems; security of data; virtual machines; NOPFIT; debugging technique; file system integrity tool; host based file system monitoring; lguest virtual machine; multibyte NOP injection; real-time file system monitoring; system security; undefined opcode exception; virtualization technology; Cloud computing; Communication system security; Condition monitoring; File systems; Kernel; Platform virtualization; Real time systems; Software debugging; Virtual machine monitors; Virtual machining; File System Integrity Tool; Realtime System Monitoring; Virtual Machine; lguest;
Conference_Titel :
Computational Science and Its Applications (ICCSA), 2010 International Conference on
Conference_Location :
Fukuoka
Print_ISBN :
978-0-7695-3999-7
Electronic_ISBN :
978-1-4244-6462-3
DOI :
10.1109/ICCSA.2010.79