Title :
Securing KVM-Based Cloud Systems via Virtualization Introspection
Author :
Sheng-Wei Lee ; Fang Yu
Author_Institution :
Dept. of Manage. Inf. Syst., Nat. Chengchi Univ. Taipei, Taipei, Taiwan
Abstract :
Linux Kernel Virtual Machine (KVM) is one of the most commonly deployed hypervisor drivers in the IaaS layer of cloud computing ecosystems. The hypervisor provides a full-virtualization environment that intends to virtualize as much hardware and systems as possible, including CPUs, network interfaces and chipsets. With KVM, heterogeneous operating systems can be installed in Virtual Machines (VMs) in an homogeneous environment. However, it has been shown that various breaches due to software defects may cause damages on such a cloud ecosystem. We propose a new Virtualization Introspection System (VIS) to protect the host as well as VMs running on a KVM-based cloud structure from malicious attacks. VIS detects and intercepts attacks from VMs by collecting their static and dynamic status. We then replay the attacks on VMs and leverage artificial intelligence techniques to derive effective decision rules with unsupervised learning nature. The preliminary result shows the promise of the presented approach against several modern attacks on CVE-based vulnerabilities.
Keywords :
Linux; cloud computing; computer network security; device drivers; operating system kernels; unsupervised learning; virtual machines; virtualisation; CVE-based vulnerabilities; IaaS layer; KVM-based cloud structure; KVM-based cloud system security; Linux kernel virtual machine; artificial intelligence techniques; cloud computing ecosystems; cloud ecosystem; decision rules; dynamic status; full-virtualization environment; heterogeneous operating systems; homogeneous environment; hypervisor drivers; malicious attacks; software defects; static status; unsupervised learning; virtualization introspection system; Analytical models; Computer hacking; Monitoring; Software; Virtual machine monitors; Virtualization; GHSOM; cloud systems; monitor; security; virtualization;
Conference_Titel :
System Sciences (HICSS), 2014 47th Hawaii International Conference on
Conference_Location :
Waikoloa, HI
DOI :
10.1109/HICSS.2014.617