• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
成果搜索

author:

Liu, Weijie (Liu, Weijie.) [1] | Liu, Ximeng (Liu, Ximeng.) [2] (Scholars:刘西蒙) | Li, Zhi (Li, Zhi.) [3] | Liu, Bin (Liu, Bin.) [4] | Yu, Rongwei (Yu, Rongwei.) [5] | Wang, Lina (Wang, Lina.) [6]

Indexed by:

EI SCIE

Abstract:

Cloud attack provenance is a well-established industrial practice for assuring transparency and accountability for a service provider to tenants. However, the multi-tenancy and self-service nature coupled with the sheer size of a cloud implies many unique challenges to cloud forensics. Although Virtual Machine Introspection (VMI) is a powerful tool for attack provenance due to the privilege isolation, the stealthiness of state-of-the-art attacks and the lack of precise information make existing attack provenance solutions difficult to fulfill real-time forensics when tracking enormous suspicious behaviors. To this end, we propose an instruction-level tracing framework for inspecting the presence of attacks by dynamically tracking shared processor hardware event patterns and analyzing the attack traces. To overcome the challenges of real-time detection and provenance, we advocate Last Branch Record (LBR) profiling, to extract the suspicious execution flows. With the hardware assistance and software-based virtualization introspection, we show that the framework can provide an effective response to threats in different cases, thereby enabling a quick attack provenance with high fidelity. The evaluation shows that our prototype introduces negligible performance penalties.

Keyword:

Cloud computing Cloud forensics Hardware last branch recording Monitoring Semantics Software virtual machine introspection Virtual machine monitors Virtual machining

Community:

  • [ 1 ] [Liu, Weijie]Indiana Univ, Luddy Sch Informat Comp & Engn, Bloomington, IN 47408 USA
  • [ 2 ] [Liu, Ximeng]Fuzhou Univ, Coll Comp & Data Sci, Fuzhou 350116, Peoples R China
  • [ 3 ] [Li, Zhi]Huazhong Univ Sci & Technol, Sch Cyber Sci & Engn, Wuhan 430074, Peoples R China
  • [ 4 ] [Liu, Bin]Hubei Univ, Sch Comp & Informat Engn, Wuhan 430062, Peoples R China
  • [ 5 ] [Yu, Rongwei]Wuhan Univ, Sch Cyber Sci & Engn, Wuhan 430079, Peoples R China
  • [ 6 ] [Wang, Lina]Wuhan Univ, Sch Cyber Sci & Engn, Wuhan 430079, Peoples R China

Reprint 's Address:

Show more details

Version:

Related Keywords:

Related Article:

Source :

IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY

ISSN: 1556-6013

Year: 2022

Volume: 17

Page: 2311-2323

6 . 8

JCR@2022

6 . 3 0 0

JCR@2023

ESI Discipline: COMPUTER SCIENCE;

ESI HC Threshold:61

JCR Journal Grade:1

CAS Journal Grade:1

Cited Count:

WoS CC Cited Count: 4

SCOPUS Cited Count: 6

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 0

Affiliated Colleges:

Online/Total:218/11069802
Address:FZU Library(No.2 Xuyuan Road, Fuzhou, Fujian, PRC Post Code:350116) Contact Us:0591-22865326
Copyright:FZU Library Technical Support:Beijing Aegean Software Co., Ltd. 闽ICP备05005463号-1