- Title
- On the design of virtual machine intrusion detection system
- Creator
- Tupakula, Udaya; Varadharajan, Vijay
- Relation
- 12th IFIP/IEEE International Symposium on Integrated Network Management (IM 2011) . Proceedings of the 12th IFIP/IEEE International Symposium on Integrated Network Management (Dublin, Ireland 23-27 May, 2011) p. 682-685
- Publisher Link
- http://dx.doi.org/10.1109/INM.2011.5990655
- Publisher
- Institute of Electrical and Electronics Engineers (IEEE)
- Resource Type
- conference paper
- Date
- 2011
- Description
- In this paper we propose comprehensive security architecture called VICTOR to deal with different types of attacks on virtual machines. Our model takes into account the specific characteristics of operating system and applications running in each virtual machine (VM) at a fine granular level to deal with the attacks. Our architecture has several components such as entity validation, intrusion detection engine and dynamic analyzer. The entity validation component is used in the detection of attack traffic with spoofed source address, secure logging, and capturing information of the operating system and applications running in the virtual machines. The intrusion detection engine component is used for detection of known attacks and suspicious behaviour by monitoring the incoming and outgoing traffic of virtual machines. The dynamic analyzer is used for detection and validation of suspicious processes, detection of zero day attacks and fine granular isolation of malicious process or application that is generating the attack traffic.
- Subject
- virtual machine monitorsy; security architecture; intrusion detection
- Identifier
- http://hdl.handle.net/1959.13/1357013
- Identifier
- uon:31850
- Identifier
- ISBN:9781424492213
- Language
- eng
- Reviewed
- Hits: 491
- Visitors: 618
- Downloads: 2
Thumbnail | File | Description | Size | Format |
---|