ISCAS OpenIR  > 2010软件所会议论文
cross-layer comprehensive intrusion harm analysis for production workload server systems
Zhang Shengzhi; Jia Xiaoqi; Liu Peng; Jing Jiwu
2010
Conference Name26th Annual Computer Security Applications Conference, ACSAC 2010
SourceProceedings - Annual Computer Security Applications Conference, ACSAC
Pages297-306
Conference Date40883
Conference PlaceAustin, TX, United states
Indexed Typeei
Publish PlaceUnited States
ISSN10639527
ISBN9781450000000
Department(1) Department of Computer Science and Engineering, Pennsylvania State University, University Park, PA, United States; (2) State Key Laboratory of Information Security, Institute of Software, Chinese Academy of Sciences, China; (3) College of Information Sciences and Technology, Pennsylvania State University, University Park, PA, United States; (4) State Key Laboratory of Information Security, Graduate University, Chinese Academy of Sciences, China
English AbstractAnalyzing the (harm of) intrusion to enterprise servers is an onerous and error-prone work. Though dynamic taint tracking enables automatic fine-grained intrusion harm analysis for enterprise servers, the significant runtime overhead introduced is generally intolerable in the production workload environment. Thus, we propose PEDA (Production Environment Damage Analysis) system, which decouples the onerous analysis work from the online execution of the production servers. Once compromised, the "has-been-infected" execution is analyzed during high fidelity replay on a separate instrumentation platform. The replay is implemented based on the heterogeneous virtual machine migration. The servers' online execution runs atop fast hardware-assisted virtual machines (such as Xen for near native speed), while the infected execution is replayed atop binary instrumentation virtual machines (such as Qemu for the implementation of taint analysis). From identified intrusion symptoms, PEDA is capable of locating the fine-grained taint seed by integrating the backward system call dependency tracking and one-step-forward taint information flow auditing. Started with the fine-grained taint seed, PEDA applies dynamic taint analysis during the replayed execution. Evaluation demonstrates the efficiency of PEDA system with runtime overhead as low as 5%. The real-life intrusion studies successfully show the comprehensiveness and the precision of PEDA's intrusion harm analysis. © 2010 ACM.
KeywordComputer Simulation Instruments Security Systems Servers
SponsorshipApplied Computer Security Associates (ACSA)
Language英语
Content Type会议论文
URIhttp://ir.iscas.ac.cn/handle/311060/8712
Collection2010软件所会议论文
Recommended Citation
GB/T 7714
Zhang Shengzhi,Jia Xiaoqi,Liu Peng,et al. cross-layer comprehensive intrusion harm analysis for production workload server systems[C]. United States,2010:297-306.
Files in This Item:
File Name/Size DocType Version Access License
p297-zhang.pdf(1069KB) 限制开放--Application Full Text
Related Services
Recommend this item
Bookmark
Usage statistics
Export to Endnote
Google Scholar
Similar articles in Google Scholar
[Zhang Shengzhi]'s Articles
[Jia Xiaoqi]'s Articles
[Liu Peng]'s Articles
Baidu academic
Similar articles in Baidu academic
[Zhang Shengzhi]'s Articles
[Jia Xiaoqi]'s Articles
[Liu Peng]'s Articles
Bing Scholar
Similar articles in Bing Scholar
[Zhang Shengzhi]'s Articles
[Jia Xiaoqi]'s Articles
[Liu Peng]'s Articles
Terms of Use
No data!
Social Bookmark/Share
All comments (0)
No comment.
 

Items in the repository are protected by copyright, with all rights reserved, unless otherwise indicated.