学位论文详细信息
Towards Self-Healing Systems: Re-establishing Trust in Compromised Systems
Virtual machine;End-user security;Intrusion detection;Intrusion recovery;Rootkits
Grizzard, Julian B. ; Electrical and Computer Engineering
University:Georgia Institute of Technology
Department:Electrical and Computer Engineering
关键词: Virtual machine;    End-user security;    Intrusion detection;    Intrusion recovery;    Rootkits;   
Others  :  https://smartech.gatech.edu/bitstream/1853/10519/1/grizzard_julian_b_200605_phd.pdf
美国|英语
来源: SMARTech Repository
PDF
【 摘 要 】

Computer systems are subject to a range of attacks that can compromise their intended operations.Conventional wisdom states that once a system has been compromised, the only way to recover is to format and reinstall.In this work, we present methods to automatically recover or self-heal from a compromise.We term the system an intrusion recovery system.The design consists of a layered architecture in which the production system and intrusion recovery system run in separate isolated virtual machines.The intrusion recovery system monitors the integrity of the production system and repairs state if a compromise is detected.A method is introduced to track the dynamic control flow graph of the production system guest kernel.A prototype of the system was built and tested against a suite of rootkit attacks.The system was able to recover from all attacks at a cost of about a 30% performance penalty.

【 预 览 】
附件列表
Files Size Format View
Towards Self-Healing Systems: Re-establishing Trust in Compromised Systems 818KB PDF download
  文献评价指标  
  下载次数:8次 浏览次数:16次