中国科学院机构知识库网格
Chinese Academy of Sciences Institutional Repositories Grid
cross-layer comprehensive intrusion harm analysis for production workload server systems

文献类型:会议论文

作者Zhang Shengzhi ; Jia Xiaoqi ; Liu Peng ; Jing Jiwu
出版日期2010
会议名称26th Annual Computer Security Applications Conference, ACSAC 2010
会议日期40883
会议地点Austin, TX, United states
关键词Computer simulation Instruments Security systems Servers
页码297-306
英文摘要Analyzing the (harm of) intrusion to enterprise servers is an onerous and error-prone work. Though dynamic taint tracking enables automatic fine-grained intrusion harm analysis for enterprise servers, the significant runtime overhead introduced is generally intolerable in the production workload environment. Thus, we propose PEDA (Production Environment Damage Analysis) system, which decouples the onerous analysis work from the online execution of the production servers. Once compromised, the "has-been-infected" execution is analyzed during high fidelity replay on a separate instrumentation platform. The replay is implemented based on the heterogeneous virtual machine migration. The servers' online execution runs atop fast hardware-assisted virtual machines (such as Xen for near native speed), while the infected execution is replayed atop binary instrumentation virtual machines (such as Qemu for the implementation of taint analysis). From identified intrusion symptoms, PEDA is capable of locating the fine-grained taint seed by integrating the backward system call dependency tracking and one-step-forward taint information flow auditing. Started with the fine-grained taint seed, PEDA applies dynamic taint analysis during the replayed execution. Evaluation demonstrates the efficiency of PEDA system with runtime overhead as low as 5%. The real-life intrusion studies successfully show the comprehensiveness and the precision of PEDA's intrusion harm analysis. © 2010 ACM.
收录类别EI
会议主办者Applied Computer Security Associates (ACSA)
会议录Proceedings - Annual Computer Security Applications Conference, ACSAC
会议录出版地United States
语种英语
ISSN号10639527
ISBN号9781450000000
源URL[http://124.16.136.157/handle/311060/8712]  
专题软件研究所_软件所图书馆_2010软件所会议论文
推荐引用方式
GB/T 7714
Zhang Shengzhi,Jia Xiaoqi,Liu Peng,et al. cross-layer comprehensive intrusion harm analysis for production workload server systems[C]. 见:26th Annual Computer Security Applications Conference, ACSAC 2010. Austin, TX, United states. 40883.

入库方式: OAI收割

来源:软件研究所

浏览0
下载0
收藏0
其他版本

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。