3 research outputs found

    Kernel Control-Flow Integrity of Multiple Virtual Machines in Real-Time using Intel Processor Trace

    No full text
    ν•™μœ„λ…Όλ¬Έ (석사)-- μ„œμšΈλŒ€ν•™κ΅ λŒ€ν•™μ› : κ³΅κ³ΌλŒ€ν•™ 전기·정보곡학뢀, 2019. 2. 백윀ν₯.μ˜€λŠ˜λ‚  ν΄λΌμš°λ“œ μ»΄ν“¨νŒ… κΈ°μˆ μ€ 사물 인터넷 μ„œλΉ„μŠ€, 인곡지λŠ₯ μ„œλΉ„μŠ€ λ“± λ‹€μ–‘ν•œ μ„œλΉ„μŠ€λ₯Ό μœ„ν•΄ μ‚¬μš©λ˜κ³  μž‡λ‹€. ν•˜μ§€λ§Œ μ΄λ ‡κ²Œ ν΄λΌμš°λ“œμ— λ§Žμ€ 정보듀이 처리되게 λ˜λ©΄μ„œ μ΄λŸ¬ν•œ ν΄λΌμš°λ“œ μ»΄ν“¨νŒ… ν™˜κ²½μ— λŒ€ν•œ λ³΄μ•ˆ λ¬Έμ œμ— λŒ€ν•œ μš°λ €λ„ 컀지고 μžˆλŠ” 상황이닀. 이λ₯Ό μœ„ν•΄ ν΄λΌμš°λ“œ μ»΄ν“¨νŒ… ν™˜κ²½μ—μ„œ κ°€μƒλ¨Έμ‹ μ˜ 무결성을 보μž₯ν•˜κΈ° μœ„ν•œ λ‹€μ–‘ν•œ 연ꡬ가 μ§„ν–‰λ˜μ—ˆμ§€λ§Œ, 아직 가상머신 μ»€λ„μ˜ μ‹€ν–‰ 흐름 λ¬΄κ²°μ„±μ˜ κ²½μš°μ—λŠ” 컀널 μ½”λ“œλ₯Ό μˆ˜μ •ν•΄μ•Όν•  뿐 μ•„λ‹ˆλΌ 효율적으둜 λ³΄ν˜Έλ„ ν•˜μ§€ λͺ»ν•˜μ˜€λ‹€. λ˜ν•œ μ‹€μ œ ν΄λΌμš°λ“œ ν™˜κ²½μ—μ„œλŠ” λ‹€μˆ˜μ˜ 가상머신이 λ™μ‹œμ— μ‹€ν–‰λ˜λ©° 각각의 가상머신이 μ„œλ‘œ λ‹€λ₯Έ μ»€λ„λ‘œ λ™μž‘ν•  수 있기 λ•Œλ¬Έμ— 가상머신듀 κ°„μ˜ ꡬ뢄을 ν•„μš”λ‘œ ν•œλ‹€. 이에 이번 λ…Όλ¬Έμ—μ„œλŠ” ν΄λΌμš°λ“œ ν™˜κ²½μ—μ„œ 가상머신 μ»€λ„μ˜ μˆ˜μ • 없이 μ‹€μ‹œκ°„μœΌλ‘œ λ‹€μˆ˜μ˜ 가상머신에 λŒ€ν•΄ 효율적으둜 가상머신 μ»€λ„μ˜ μ‹€ν–‰ 흐름 무결성을 λ³΄ν˜Έν•˜λŠ” RTC-VM을 μ œμ•ˆν•œλ‹€. 이λ₯Ό μœ„ν•΄ RTC-VM은 λ™μ‹œμ— μ‹€ν–‰λ˜λŠ” μ—¬λŸ¬ 개의 가상머신을 κ΅¬λΆ„ν•˜μ—¬ 각각에 λŒ€ν•΄ 무결성을 검증할 수 있게 κ΅¬ν˜„λ˜μ—ˆλ‹€. λ˜ν•œ, 가상머신 μ‹€ν–‰ 흐름 정보에 λŒ€ν•œ μœ μ‹€ 없이 μ‹€μ‹œκ°„μœΌλ‘œ λͺ¨λ‹ˆν„°λ§ν•  수 μžˆλ‹€. 그리고 효율적으둜 μˆ˜ν–‰ 흐름 정보λ₯Ό μ–»κΈ° μœ„ν•΄ RTC-VM은 졜근 인텔 μ•„ν‚€ν…μ²˜μ—μ„œ μ§€μ›ν•˜λŠ” ν•˜λ“œμ›¨μ–΄ κΈ°λŠ₯인 Processor Trace (PT)λ₯Ό ν™œμš©ν•˜μ˜€μœΌλ©°, κ°€μƒλ¨Έμ‹ μ˜ μ„±λŠ₯ μ‹€ν—˜μ—μ„œλ„ 7.5%의 적은 μ„±λŠ₯ μ˜€λ²„ν—€λ“œλ‘œ μˆ˜ν–‰ 흐름 무결성을 보μž₯ν•˜μ˜€λ‹€.Nowadays cloud computing technology is used for a variety of services, such as the internet of things and artificial intelligence. However, as more data is being processed in the cloud, there is growing concern about security issues in the cloud computing environment. To solve this concern, many studies have been conducted to ensure the integrity of virtual machines in a cloud computing environment. However, in the case of the control flow integrity for the virtual machine, existing studies are not only necessary to modify the kernel code, but also cannot protect it efficiently. Also, since multiple VMs which can have different kernel one another run simultaneously in real-world cloud computing environment, it is required to identify VMs. In this paper, we propose RTC-VM which efficiently protects the control flow integrity of VM kernel for multiple VMs without modification of VM kernel in real-time. For this purpose, RTC-VM is implemented to enforce control flow integrity of each VM with identifying multiple VMs which run concurrently. In addition, RTC-VM can monitor in real-time without loss of execution control-flow information. For efficient monitoring, RTC-VM utilizes Processor Trace (PT), a hardware feature that is recently supported by Intel architecture. According to the experimental results, RTC-VM incurs on average 7.5% overhead.제 1 μž₯ μ†Œκ°œ 1 제 2 μž₯ λ°°κ²½ 및 곡격 λͺ¨λΈ 3 제 1 절 인텔 ν”„λ‘œμ„Έμ„œ 트레이슀 3 제 2 절 곡격 λͺ¨λΈ 4 제 3 μž₯ λ””μžμΈ 및 κ΅¬ν˜„ 5 제 1 절 λ””μžμΈ κ°œμš” 5 제 2 절 μ˜€ν”„λΌμΈ λ°”μ΄λ„ˆλ¦¬ 뢄석 6 제 3 절 가상머신 λ‹¨μœ„ 버퍼 관리 7 제 4 절 μ‹€μ‹œκ°„μ„± 보μž₯ 8 제 5 절 무결성 검증 μ•Œκ³ λ¦¬μ¦˜ 10 제 4 μž₯ μ‹€ν—˜ κ²°κ³Ό 13 제 1 절 μ‹€ν—˜ ν™˜κ²½ 및 ν”„λ‘œν† νƒ€μž… κ΅¬ν˜„ 13 제 2 절 μ„±λŠ₯ μ˜€λ²„ν—€λ“œ 13 제 3 절 곡격 탐지 14 제 5 μž₯ κ΄€λ ¨ 연ꡬ 15 제 1 절 Virtaul Machine Introspection 15 제 2 절 Control Flow Integrity using Intel PT 15 제 3 절 Kernel Control Flow Integrity 15 제 6 μž₯ κ²°λ‘  17 μ°Έκ³ λ¬Έν—Œ 18 Abstract 20Maste
    corecore