• DocumentCode
    2907628
  • Title

    BlockTapping: An Online Transparent Integrity Checker for Virtual Storage

  • Author

    Fang, Haifeng

  • Author_Institution
    EMC Labs., Beijing, China
  • fYear
    2011
  • fDate
    7-9 Dec. 2011
  • Firstpage
    610
  • Lastpage
    617
  • Abstract
    The integrity of virtual storage has become a very important issue in the virtual computing environment (like Xen-based computing platform). Current integrity detection systems have some disadvantages, for example, they cannot protect themselves well or the dependence between the detection results and the target system is high. We refer to the problem as lack of transparency. This paper presents a novel online integrity checker, Block Tapping, which ensures its security benefiting from the isolation property of virtual machine. Block tapping monitors the block-level data streams transparently through block-to-file semantic-translation at the virtual block device layer. Based on the self-described information of virtual storages, Block Tapping detects the file-level malicious behaviors independent of the internal state of the compromised virtual machine. Experiments show that the prototype system successfully captures 13 typical user-mode root kit attacks against virtual storage, and the performance overhead is acceptable.
  • Keywords
    data integrity; data privacy; file organisation; virtual machines; virtual storage; Xen-based computing platform; block-level data stream; block-to-file semantic-translation; blocktapping; file-level malicious behavior; online transparent integrity checker; virtual block device layer; virtual computing environment; virtual machine; virtual storage; Databases; Kernel; Monitoring; Prototypes; Semantics; Synchronization; Virtual machining; Data Integrity; Transparent Detection; Virtual Storage;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel and Distributed Systems (ICPADS), 2011 IEEE 17th International Conference on
  • Conference_Location
    Tainan
  • ISSN
    1521-9097
  • Print_ISBN
    978-1-4577-1875-5
  • Type

    conf

  • DOI
    10.1109/ICPADS.2011.34
  • Filename
    6121331