Live and Trustworthy Forensic Analysis of Commodity Production Systems

نویسندگان

  • Lorenzo Martignoni
  • Aristide Fattori
  • Roberto Paleari
  • Lorenzo Cavallaro
چکیده

We present HyperSleuth, a framework that leverages the virtualization extensions provided by commodity hardware to securely perform live forensic analysis of potentially compromised production systems. HyperSleuth provides a trusted execution environment that guarantees four fundamental properties. First, an attacker controlling the system cannot interfere with the analysis and cannot tamper the results. Second, the framework can be installed as the system runs, without a reboot and without loosing any volatile data. Third, the analysis performed is completely transparent to the OS and to an attacker. Finally, the analysis can be periodically and safely interrupted to resume normal execution of the system. On top of HyperSleuth we implemented three forensic analysis applications: a lazy physical memory dumper, a lie detector, and a system call tracer. The experimental evaluation we conducted demonstrated that even time consuming analysis, such as the dump of the content of the physical memory, can be securely performed without interrupting the services offered by the system.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Chapter 16 REMOTE FORENSIC ANALYSIS OF PROCESS CONTROL SYSTEMS

Forensic analysis can help maintain the security of process control systems: identifying the root cause of a system compromise or failure is useful for mitigating current and future threats. However, forensic analysis of control systems is complicated by three factors. First, live analysis must not impact the performance and functionality of a control system. Second, the analysis should be perf...

متن کامل

Life cycle assessment of high- and low-profitability commodity and deep-bedded niche swine production systems in the Upper Midwestern United States

0308-521X/$ see front matter 2010 Elsevier Ltd. A doi:10.1016/j.agsy.2010.07.001 * Corresponding author. Tel.: +1 902 405 9338 fax: E-mail address: [email protected] (N. Pelletie We used ISO-compliant life cycle assessment to evaluate the comparative environmental performance of highand low-profitability commodity and deep-bedded niche swine production systems in the Upper Midwestern Unite...

متن کامل

Application of Tabu Search to a Special Class of Multicommodity Distribution Systems

Multicommodity distribution problem is one of the most interesting and useful models in mathematical programming due to its major role in distribution networks. The purpose of this paper is to describe and solve a special class of multicommodity distribution problems in which shipment of a commodity from a plant to a customer would go through different distribution centers. The problem is t...

متن کامل

Agricultural Employment through the Removal of Barriers of Agricultural Products Supply To Commodity Exchanges (A Case of Khorasan Rezavi Province)

       Creating full employment is one of the macroeconomic goals of politicians in all countries. Unemployment is one of the major problems facing the Iranian economy, which its reduction, requires investment in various sectors of the economy and production boom. Improving the marketing situation of agricultural products can boost production, increase income and employment in agriculture. An a...

متن کامل

TrustOSV: Building Trustworthy Executing Environment with Commodity Hardware for a Safe Cloud

The Infrastructure as a Service (IaaS) cloud computing model is widely used in current IT industry, providing the cloud users virtual machines as the executing environment. However, current executing environment the cloud provided is not trustworthy. For a user’s executing environment faces threats from malicious cloud users who aim at attacking the underlying virtualization software (virtual m...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2010