A VMM-based intrusion prevention system in cloud computing environment

作者:Jin Hai; Xiang Guofu; Zou Deqing*; Wu Song; Zhao Feng; Li Min; Zheng Weide
来源:Journal of Supercomputing, 2013, 66(3): 1133-1151.
DOI:10.1007/s11227-011-0608-2

摘要

With the development of information technology, cloud computing becomes a new direction of grid computing. Cloud computing is user-centric, and provides end users with leasing service. Guaranteeing the security of user data needs careful consideration before cloud computing is widely applied in business. Virtualization provides a new approach to solve the traditional security problems and can be taken as the underlying infrastructure of cloud computing. In this paper, we propose an intrusion prevention system, VMFence, in a virtualization-based cloud computing environment, which is used to monitor network flow and file integrity in real time, and provide a network defense and file integrity protection as well. Due to the dynamicity of the virtual machine, the detection process varies with the state of the virtual machine. The state transition of the virtual machine is described via Definite Finite Automata (DFA). We have implemented VMFence on an open-source virtual machine monitor platform-Xen. The experimental results show our proposed method is effective and it brings acceptable overhead.