Title :
BlockTapping: An Online Transparent Integrity Checker for Virtual Storage
Author_Institution :
EMC Labs., Beijing, China
Abstract :
The integrity of virtual storage has become a very important issue in the virtual computing environment (like Xen-based computing platform). Current integrity detection systems have some disadvantages, for example, they cannot protect themselves well or the dependence between the detection results and the target system is high. We refer to the problem as lack of transparency. This paper presents a novel online integrity checker, Block Tapping, which ensures its security benefiting from the isolation property of virtual machine. Block tapping monitors the block-level data streams transparently through block-to-file semantic-translation at the virtual block device layer. Based on the self-described information of virtual storages, Block Tapping detects the file-level malicious behaviors independent of the internal state of the compromised virtual machine. Experiments show that the prototype system successfully captures 13 typical user-mode root kit attacks against virtual storage, and the performance overhead is acceptable.
Keywords :
data integrity; data privacy; file organisation; virtual machines; virtual storage; Xen-based computing platform; block-level data stream; block-to-file semantic-translation; blocktapping; file-level malicious behavior; online transparent integrity checker; virtual block device layer; virtual computing environment; virtual machine; virtual storage; Databases; Kernel; Monitoring; Prototypes; Semantics; Synchronization; Virtual machining; Data Integrity; Transparent Detection; Virtual Storage;
Conference_Titel :
Parallel and Distributed Systems (ICPADS), 2011 IEEE 17th International Conference on
Conference_Location :
Tainan
Print_ISBN :
978-1-4577-1875-5
DOI :
10.1109/ICPADS.2011.34