We use cookies to improve your experience with our site.

一种基于反检测指标的虚拟机存储隐蔽信道威胁限制算法

An Efficient Approach for Mitigating Covert Storage Channel Attacks in Virtual Machines by the Anti-Detection Criterion

  • 摘要: 隐蔽信道是信息安全领域中的重要威胁,现有许多研究都重点关注隐蔽信道的攻防技术。目前大部分隐蔽信道威胁限制方法都是基于现有威胁度量指标的,例如容量、准确率和短消息等指标。这些指标能够度量存储隐蔽信道的传输能力。但是现有指标很难全面地反映通信过程中的关键要素,例如共享资源、编码机制和同步机制,因此很难评估不断更新的存储隐蔽信道的反检测性和复杂性。因此,本文提出了反检测标准以消除上述局限性。同时,尽管目前的限制技术能够在一定程度上限制隐蔽信道的威胁,但是却不可避免的给系统带来较大的额外负荷,因而使得限制技术的可用性降低。本文提出了一种基于反检测指标的限制算法来降低对系统性能的影响。该限制算法在限制虚拟机存储隐蔽信道威胁的同时,减少给系统的性带来的负荷。实验结果表明,本文提出的限制算法可以有效地限制存储隐蔽信道攻击。与经典的Pump限制算法相比,本文的算法显著地降低了系统的开销。

     

    Abstract: Covert channels have been an effective means for leaking confidential information across security domains and numerous studies are available on typical covert channels attacks and defenses. Existing covert channel threat restriction solutions are based on the threat estimation criteria of covert channels such as capacity, accuracy, and short messages which are effective in evaluating the information transmission ability of a covert (storage) channel. However, these criteria cannot comprehensively reflect the key factors in the communication process such as shared resources and synchronization and therefore are unable to evaluate covertness and complexity of increasingly upgraded covert storage channels. As a solution, the anti-detection criterion was introduced to eliminate these limitations of cover channels. Though effective, most threat restriction techniques inevitably incur high performance overhead and hence become impractical. In this work, we avoid such overheads and present a restriction algorithm based on the anti-detection criterion to restrict threats that are associated with covert storage channels in virtual machines while maintaining the resource efficiency of the systems. Experimental evaluation shows that our proposed solution is able to counter covert storage channel attacks in an effective manner. Compared with Pump, a well-known traditional restriction algorithm used in practical systems, our solution significantly reduces the system overhead.

     

/

返回文章
返回