loading...
VNIDA: Building an IDS Architecture Using VMM-Based Non-Intrusive Approach
Adelaide, Australia January 23-January 24
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/WKDD.2008.135First International Workshop on Knowl ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Intrusion detection system (IDS) has been introduced and broadly applied to prevent unauthorized access to system resource and data for several years. However, many problems are still not well resolved in most of IDS, such as detection evasion, intrusion containment. In order to resolve these problems, we propose a novel flexible architecture VNIDA which is based on virtual machine monitor (VMM) and has no-intrusive behavior to target system after studying popular IDS architectures. In this architecture, a separate intrusion detection domain (IDD) is added to provide intrusion detection services for all virtual machines. Specially, an IDD helper is introduced to take response to the intrusions according to the security policies. Moreover, event sensors and IDS stub, as the core components of IDS, are separately isolated from target systems, so strong reliability is also achieved in this architecture. To show the feasibility of the VNIDA, we implement a prototype based on the proposed architecture. Based on the prototype, we employed some rootkits to evaluate our VNIDA, and the results shows that VNIDA has the ability to detect them efficiently, even some potential intrusions. In addition, system performance evaluation also shows that VNIDA only introduce less than 1.25% extra overhead.
Citation:
Xiantao Zhang, Qi Li, Sihan Qing, Huanguo Zhang, "VNIDA: Building an IDS Architecture Using VMM-Based Non-Intrusive Approach," wkdd, pp.594-600, First International Workshop on Knowledge Discovery and Data Mining (WKDD 2008), 2008
Usage of this product signifies your acceptance of the Terms of Use.


Suggestions