Design and implementation of hiding method for file manipulation of essential services by system call proxy using virtual machine monitor

被引:4
|
作者
Sato, Masaya [1 ]
Taniguchi, Hideo [1 ]
Yamauchi, Toshihiro [1 ]
机构
[1] Okayama Univ, Grad Sch Nat Sci & Technol, Okayama, Japan
关键词
virtual machine monitor; file manipulation; proxy execution; hiding method; essential services; computer security; attack mitigation; attack prevention; system call monitoring; file access;
D O I
10.1504/IJSSC.2019.100007
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security or system management software is essential for keeping systems secure. To deter attacks on essential services, hiding information related to essential services is helpful. This paper describes the design, the implementation, and the evaluation of a method to make files invisible to all services except their corresponding essential services and provides access methods to those files in a virtual machine (VM). In the proposed method, the virtual machine monitor (VMM) monitors the system call, which invoked by an essential process to access essential files, and requests proxy execution to the proxy process on another VM. The VMM returns the result and skips the execution of the original system call on the protection target VM. Thus, access to essential files by the essential service is skipped on the protection target VM, but the essential service can access the file content.
引用
收藏
页码:1 / 10
页数:10
相关论文
共 4 条
  • [1] Hiding File Manipulation of Essential Services by System Call Proxy
    Sato, Masaya
    Taniguchi, Hideo
    Yamauchi, Toshihiro
    ADVANCES IN NETWORK-BASED INFORMATION SYSTEMS, NBIS-2018, 2019, 22 : 853 - 863
  • [2] Hiding Communication of Essential Services by System Call Proxy
    Okuda, Yuuki
    Sato, Masaya
    Taniguchi, Hideo
    2018 SIXTH INTERNATIONAL SYMPOSIUM ON COMPUTING AND NETWORKING (CANDAR 2018), 2018, : 47 - 56
  • [3] A proxy communication method in machine to machine system to enable the device connection to different multiple services and its implementation
    Kitagami, Shinji
    Kaneko, Yosuke
    Yasuda, Akihisa
    Minemura, Harumi
    Koizumi, Hisao
    IEEJ Transactions on Electronics, Information and Systems, 2012, 132 (04) : 516 - 525
  • [4] A Proxy Communication Method in Machine-to-Machine System to Enable the Device Connection to Different Multiple Services and Its Implementation
    Kitagami, Shinji
    Kaneko, Yosuke
    Yasuda, Akihisa
    Minemura, Harumi
    Koizumi, Hisao
    ELECTRONICS AND COMMUNICATIONS IN JAPAN, 2013, 96 (12) : 74 - 84