• Home
  • Search
  • Cross-layer comprehensive intrusion harm analysis for production workload server systems
  • Cite Icon9
  • https://doi.org/10.1145/1920261.1920306Copy DOI Icon

Cross-layer comprehensive intrusion harm analysis for production workload server systems

  • Dec 6, 2010
  • Shengzhi Zhang +3 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Analyzing the (harm of) intrusion to enterprise servers is an onerous and error-prone work. Though dynamic taint tracking enables automatic fine-grained intrusion harm analysis for enterprise servers, the significant runtime overhead introduced is generally intolerable in the production workload environment. Thus, we propose PEDA (Production Environment Damage Analysis) system, which decouples the onerous analysis work from the online execution of the production servers. Once compromised, the "has-been-infected" execution is analyzed during high fidelity replay on a separate instrumentation platform. The replay is implemented based on the heterogeneous virtual machine migration. The servers' online execution runs atop fast hardware-assisted virtual machines (such as Xen for near native speed), while the infected execution is replayed atop binary instrumentation virtual machines (such as Qemu for the implementation of taint analysis). From identified intrusion symptoms, PEDA is capable of locating the fine-grained taint seed by integrating the backward system call dependency tracking and one-step-forward taint information flow auditing. Started with the fine-grained taint seed, PEDA applies dynamic taint analysis during the replayed execution. Evaluation demonstrates the efficiency of PEDA system with runtime overhead as low as 5%. The real-life intrusion studies successfully show the comprehensiveness and the precision of PEDA's intrusion harm analysis.

Similar Papers
  • Conference Article
  • Citations3

Efficient Taint Analysis with Taint Behavior Summary

  • Apr 01, 2011
  • Ruoyu Zhang +2
  • PDF
  • Research Article
  • Citations18

Fine-grained preemption analysis for latency investigation across virtual machines

  • Dec 01, 2014
  • Journal of Cloud Computing
  • Mohamad Gebai +2
  • PDF
  • Conference Article
  • Citations13

RapidVMI: Fast and multi-core aware active virtual machine introspection

  • Aug 17, 2021
  • Thomas Dangl +2
  • Conference Article
  • Citations21

Cross-program taint analysis for IoT systems

  • Mar 30, 2020
  • Amit Mandal +4
  • Conference Article
  • Citations8

Optimize Performance of Virtual Machine Checkpointing via Memory Exclusion

  • Aug 01, 2009
  • Haikun Liu +2
  • Conference Article
  • Citations176

Concurrent Direct Network Access for Virtual Machine Monitors

  • Jan 01, 2007
  • Jeffrey Shafer +6
  • Research Article

The Propagation Strategy Model of Taint Analysis

  • Apr 01, 2020
  • Journal of Physics: Conference Series
  • Yuzhu Ren +2
  • Conference Article
  • Citations1

NnTaint: An Optimized Dynamic Taint Analysis Method Based on Neural Network

  • Aug 23, 2022
  • Yuming Zhu +1
  • Conference Article
  • Citations18

Performance Implications of Virtualization and Hyper-Threading on High Energy Physics Applications in a Grid Environment

  • Apr 04, 2005
  • L Gilbert +7
  • Book Chapter
  • Citations2

Workload-Aware VM Consolidation in Cloud Based on Max-Min Ant System

  • Jan 01, 2017
  • Hongjie Zhang +4
  • Conference Article
  • Citations20

Virtual batching: Request batching for energ conservation in virtualized servers

  • Jun 01, 2010
  • Yefu Wang +2
  • Book Chapter
  • Citations2

A Framework of Static Analyzer for Taint Analysis of Binary Executable File

  • Jan 01, 2013
  • Young-Hyun Choi +4
  • Conference Article
  • Citations15

Performance Interference of Memory Thrashing in Virtualized Cloud Environments: A Study of Consolidated n-Tier Applications

  • Jun 01, 2016
  • Junhee Park +5
  • Conference Article
  • Citations4

DTAD: A Dynamic Taint Analysis Detector for Information Security

  • Jul 01, 2008
  • Zhiwen Bai +5
  • Research Article
  • Citations3

Fine-grained multilayer virtualized systems analysis

  • Dec 01, 2016
  • Journal of Cloud Computing
  • Cédric Biancheri +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.