Detailed Information

Cited 1 time in webofscience Cited 2 time in scopus
Metadata Downloads

SBGen: A Framework to Efficiently Supply Runtime Information for a Learning-Based HIDS for Multiple Virtual Machines

Full metadata record
DC Field Value Language
dc.contributor.authorSeo, Jiwon-
dc.contributor.authorBang, Inyoung-
dc.contributor.authorYou, Junseung-
dc.contributor.authorCho, Yeongpil-
dc.contributor.authorPaek, Yunheung-
dc.date.accessioned2022-07-07T11:12:37Z-
dc.date.available2022-07-07T11:12:37Z-
dc.date.created2021-05-12-
dc.date.issued2020-11-
dc.identifier.issn2169-3536-
dc.identifier.urihttps://scholarworks.bwise.kr/hanyang/handle/2021.sw.hanyang/144385-
dc.description.abstractMuch compelling evidence urges that the isolation provided by the hypervisor in a virtualized system is not complete at all, and in practice can be neutralized by elaborated adversaries, which consequently emphasizes the need of techniques to detect attacks on the guest VM kernels. In this regard, learning-based HIDSs have received much attention, which inspect the internals of each VM through monitoring models built by machine learning techniques. The inspection capability of learning-based HIDSs depends on the quality of the monitoring models, which in turn can be improved by using rich runtime information reflecting the exact behavior of VMs. However, as extracting such runtime behavior information is onerous on account of its vast quantity, many learning-based HIDSs have resorted to using only fragmentary runtime behavior information. To address this problem, in this paper, we present SBGen, a framework for efficient extraction of rich runtime behavior information of VMs, namely the system call traces and the execution paths of the kernel taken to serve system calls. To trace execution of the kernel efficiently, SBGen leverages a salient hardware feature, Intel Processor Trace (PT). Once receiving the execution of the kernel traces from PT, SBGen elaborately decodes and purifies them to extract execution paths of the kernel associated with system calls. The extracted runtime behavior information of VMs is fed into learning-based HIDSs to improve their detection accuracy. Our experiments show that SBGen can extract and supply runtime behavior information efficiently enough for learning-based HIDSs to detect in a timely fashion real-world attacks on the guest VM kernels running in a virtualized system, while incurring a reasonable amount of performance overhead.-
dc.language영어-
dc.language.isoen-
dc.publisherIEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC-
dc.titleSBGen: A Framework to Efficiently Supply Runtime Information for a Learning-Based HIDS for Multiple Virtual Machines-
dc.typeArticle-
dc.contributor.affiliatedAuthorCho, Yeongpil-
dc.identifier.doi10.1109/ACCESS.2020.3041302-
dc.identifier.scopusid2-s2.0-85097374702-
dc.identifier.wosid000603725800001-
dc.identifier.bibliographicCitationIEEE ACCESS, v.8, pp.225356 - 225369-
dc.relation.isPartOfIEEE ACCESS-
dc.citation.titleIEEE ACCESS-
dc.citation.volume8-
dc.citation.startPage225356-
dc.citation.endPage225369-
dc.type.rimsART-
dc.type.docTypeArticle-
dc.description.journalClass1-
dc.description.isOpenAccessY-
dc.description.journalRegisteredClassscie-
dc.description.journalRegisteredClassscopus-
dc.relation.journalResearchAreaComputer Science-
dc.relation.journalResearchAreaEngineering-
dc.relation.journalResearchAreaTelecommunications-
dc.relation.journalWebOfScienceCategoryComputer Science, Information Systems-
dc.relation.journalWebOfScienceCategoryEngineering, Electrical & Electronic-
dc.relation.journalWebOfScienceCategoryTelecommunications-
dc.subject.keywordPlusINTROSPECTION-
dc.subject.keywordPlusSELF-
dc.subject.keywordAuthorRuntime-
dc.subject.keywordAuthorMonitoring-
dc.subject.keywordAuthorKernel-
dc.subject.keywordAuthorData mining-
dc.subject.keywordAuthorLogic gates-
dc.subject.keywordAuthorVirtual machining-
dc.subject.keywordAuthorInspection-
dc.subject.keywordAuthorIntel Processor Trace (PT)-
dc.subject.keywordAuthorl earning-based HIDS-
dc.subject.keywordAuthorVM monitoring-
dc.subject.keywordAuthorextraction of runtime behavior information-
dc.subject.keywordAuthorguest VM kernel execution traces-
dc.identifier.urlhttps://ieeexplore.ieee.org/document/9272991-
Files in This Item
Appears in
Collections
서울 공과대학 > 서울 컴퓨터소프트웨어학부 > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Cho, Yeong pil photo

Cho, Yeong pil
COLLEGE OF ENGINEERING (SCHOOL OF COMPUTER SCIENCE)
Read more

Altmetrics

Total Views & Downloads

BROWSE