loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
18th International Symposium on Computer Architecture and High Performance Computing (SBAC-PAD'06)
Virtual-Machine-based Intrusion Detection on File-aware Block Level Storage
Ouro Preto, MG, Brazil
October 17-October 20
ISBN: 0-7695-2704-3
Youhui Zhang, Tsinghua University, China
Yu Gu, Tsinghua University, China
Hongyi Wang, Tsinghua University, China
Dongsheng Wang, Tsinghua University, China
In this paper we present a storage-based intrusion detection system (IDS) that makes use of advantages of virtual machine (VM) and smart disk technologies. The virtual machine monitor (VMM) can prevent the IDS itself from potential attacks while the smart disk technology provides IDS with a whole view of the file system of the monitored VM. We show how to use a tool and some file system knowledge to enable the virtual disk to maintain a sector-to-file mapping table (called file-aware block level storage) as well as how to detect the changes to file content on-line. Based on these features, normal file-level intrusion detection (ID) rules can be converted to sector-level ones in order to integrate ID functions to the virtual storage. We implement such a prototype based on QEMU VMM and the OS of VM is Windows XP. Moreover the time overhead introduced by this solution is tested.
Citation:
Youhui Zhang, Yu Gu, Hongyi Wang, Dongsheng Wang, "Virtual-Machine-based Intrusion Detection on File-aware Block Level Storage," sbac-pad, pp.185-192, 18th International Symposium on Computer Architecture and High Performance Computing (SBAC-PAD'06), 2006
Usage of this product signifies your acceptance of the Terms of Use.