Live and Trustworthy Forensic Analysis of Commodity Production Systems
نویسندگان
چکیده
We present HyperSleuth, a framework that leverages the virtualization extensions provided by commodity hardware to securely perform live forensic analysis of potentially compromised production systems. HyperSleuth provides a trusted execution environment that guarantees four fundamental properties. First, an attacker controlling the system cannot interfere with the analysis and cannot tamper the results. Second, the framework can be installed as the system runs, without a reboot and without loosing any volatile data. Third, the analysis performed is completely transparent to the OS and to an attacker. Finally, the analysis can be periodically and safely interrupted to resume normal execution of the system. On top of HyperSleuth we implemented three forensic analysis applications: a lazy physical memory dumper, a lie detector, and a system call tracer. The experimental evaluation we conducted demonstrated that even time consuming analysis, such as the dump of the content of the physical memory, can be securely performed without interrupting the services offered by the system.
منابع مشابه
Chapter 16 REMOTE FORENSIC ANALYSIS OF PROCESS CONTROL SYSTEMS
Forensic analysis can help maintain the security of process control systems: identifying the root cause of a system compromise or failure is useful for mitigating current and future threats. However, forensic analysis of control systems is complicated by three factors. First, live analysis must not impact the performance and functionality of a control system. Second, the analysis should be perf...
متن کاملLife cycle assessment of high- and low-profitability commodity and deep-bedded niche swine production systems in the Upper Midwestern United States
0308-521X/$ see front matter 2010 Elsevier Ltd. A doi:10.1016/j.agsy.2010.07.001 * Corresponding author. Tel.: +1 902 405 9338 fax: E-mail address: [email protected] (N. Pelletie We used ISO-compliant life cycle assessment to evaluate the comparative environmental performance of highand low-profitability commodity and deep-bedded niche swine production systems in the Upper Midwestern Unite...
متن کاملApplication of Tabu Search to a Special Class of Multicommodity Distribution Systems
Multicommodity distribution problem is one of the most interesting and useful models in mathematical programming due to its major role in distribution networks. The purpose of this paper is to describe and solve a special class of multicommodity distribution problems in which shipment of a commodity from a plant to a customer would go through different distribution centers. The problem is t...
متن کاملAgricultural Employment through the Removal of Barriers of Agricultural Products Supply To Commodity Exchanges (A Case of Khorasan Rezavi Province)
Creating full employment is one of the macroeconomic goals of politicians in all countries. Unemployment is one of the major problems facing the Iranian economy, which its reduction, requires investment in various sectors of the economy and production boom. Improving the marketing situation of agricultural products can boost production, increase income and employment in agriculture. An a...
متن کاملTrustOSV: Building Trustworthy Executing Environment with Commodity Hardware for a Safe Cloud
The Infrastructure as a Service (IaaS) cloud computing model is widely used in current IT industry, providing the cloud users virtual machines as the executing environment. However, current executing environment the cloud provided is not trustworthy. For a user’s executing environment faces threats from malicious cloud users who aim at attacking the underlying virtualization software (virtual m...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2010