VMGuard: An Integrity Monitoring System for Management Virtual Machines

Parallel and Distributed Systems(2010)

引用 17|浏览0
暂无评分
摘要
A cloud computing provider can dynamically allocate virtual machines (VM) based on the needs of the customers, while maintaining the privileged access to the Management Virtual Machine that directly manages the hardware and supports the guest VMs. The customers must trust the cloud providers to protect the confidentiality and integrity of their applications and data. However, as the VMs from different customers are running on the same host, an attack to the management virtual machine will easily lead to the compromise of the guest VMs. Therefore, it is critical for a cloud computing system to ensure the trustworthiness of management VMs. To this end, we propose VMGuard, an integrity monitoring and detecting system for management virtual machines in a distributed environment. VMGuard utilizes a special VM, Guard Domain, which runs on each physical node to monitor the co-resident management VMs. The integrity measurements collected by the Guard Domains are sent to the VMGuard server for safe store and independent analysis. The experimental evaluation of a Xen-based prototype shows that VMGuard can quickly detect the root kit attacks while the performance overhead is low.
更多
查看译文
关键词
integrity monitoring,co-resident management vms,remote i/o,detecting system,cloud computing provider,guard domain,virtual machines,cloud providers,guest vms,management vms,cloud provider,integrity monitoring system,management virtual machine,integrity measurement,coresident management,cloud computing,independent analysis,cloud computing system,virtual machine,vmguard server,system monitoring,management virtual machines,distributed environment,kernel,engines,servers
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要