Deakin University
Browse

File(s) under permanent embargo

Supporting virtualization-aware security solutions using a systematic approach to overcome the semantic gap

conference contribution
posted on 2012-10-02, 00:00 authored by Amani Ibrahim, J Hamlyn-Harris, John Grundy, M Almorsy
A prerequisite to implementing virtualization-aware security solutions is to solve the "semantic gap" problem. Current approaches require a deep knowledge of the kernel data to manually solve the semantic gap. However, kernel data is very complex; an Operating System (OS) kernel contains thousands of data structures that have direct and indirect (pointer) relations between each other with no explicit integrity constraints. This complexity makes it impractical to use manual methods. In this paper, we present a new solution to systematically and efficiently solve the semantic gap for any OS, without any prior knowledge of the OS. We present: (i) KDD, a tool that systematically builds a precise kernel data definition for any C-based OS such as Windows and Linux. KDD generates this definition by performing points-to analysis on the kernel's source code to disambiguate the pointer relations. (ii) SVA, a security appliance that solves the semantic gap based on the generated definition, to systematically and externally map the virtual machines' physical memory and extract the runtime dynamic objects. We have implemented prototypes for KDD and SVA, and have performed different experiments to prove their effectiveness.

History

Event

Could Computing. IEEE International Conference (5th : 2012 : Honolulu, Hawaii)

Pagination

836 - 843

Publisher

IEEE

Location

Honolulu, Hawaii

Place of publication

Piscataway, N.J.

Start date

2012-06-24

End date

2012-06-29

ISBN-13

9780769547558

Language

eng

Publication classification

E Conference publication; E1.1 Full written paper - refereed

Copyright notice

2012, IEEE

Title of proceedings

CLOUD 2012 : Proceedings of the IEEE 5th International Conference on Cloud Computing, 2012

Usage metrics

    Research Publications

    Categories

    No categories selected

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC