Title :
A Secure Framework for Monitoring Operating Systems Using SPEs in Cell/B.E.
Author :
Kourai, Kenichi ; Nagata, Takuya
Author_Institution :
Kyushu Inst. of Technol., Kitakyushu, Japan
Abstract :
Recently, even operating systems are often compromised by the attackers. Since a compromised operating system affects all the applications including security software on top of it, the integrity of the operating system should be guaranteed. However, it is difficult to monitor the operating system securely. In this paper, we propose SPE Observer, which is a framework for securely monitoring operating systems using SPEs in Cell/B.E. SPE Observer guarantees the integrity and confidentiality of monitoring systems by the isolation mode of SPEs. To complement the isolation mode, SPE Observer monitors the running status of monitoring systems from an external security proxy. In addition, it schedules monitoring systems to mitigate the performance degradation of applications due to occupying SPEs. We have implemented SPE Observer in PlayStation 3 and developed the integrity monitor of the operating system. According to our experiments, it was shown that the integrity monitor on an SPE could detect a compromised operating system and that the application performance was dramatically improved by scheduling the integrity monitor.
Keywords :
observers; operating systems (computers); performance evaluation; scheduling; security of data; Cell/B.E; PlayStation 3; SPE observer; compromised operating system; external security proxy; isolation mode; operating system monitoring; performance degradation; secure framework; security software; Heart beat; Kernel; Monitoring; Observers; Relays; Security; Monitoring; multicore; operating systems; security;
Conference_Titel :
Dependable Computing (PRDC), 2012 IEEE 18th Pacific Rim International Symposium on
Conference_Location :
Niigata
Print_ISBN :
978-1-4673-4849-2
Electronic_ISBN :
978-0-7695-4885-2
DOI :
10.1109/PRDC.2012.13