Software cruising: A new technology for building concurrent software monitor

Dinghao Wu*, Peng Liu, Qiang Zeng, Donghai Tian

*此作品的通讯作者

科研成果: 书/报告/会议事项章节章节同行评审

1 引用 (Scopus)

摘要

We introduce a novel concurrent software monitoring technology, called software cruising. It leverages multicore architectures and utilizes lock-free data structures and algorithms to achieve efficient and scalable security monitoring. Applications include, but are not limited to, heap buffer integrity checking, kernel memory cruising, data structure and object invariant checking, rootkit detection, and information provenance and flow checking. In the software cruising framework, one or more dedicated threads, called cruising threads, are running concurrently with the monitored user or kernel code, to constantly check, or cruise, for security violations. We believe the software cruising technology would result in a game-changing capability in security monitoring for the cloud-based and traditional computing and network systems. We have developed two prototypical cruising systems: Cruiser, a lock-free concurrent heap buffer overflow monitor in user space, and Kruiser, a semi-synchronized non-blocking OS kernel cruiser. Our experimental results showed that software cruising can be deployed in practice with modest overhead. In user space, heap buffer overflow cruising incurs only 5 % performance overhead on average for the SPEC CPU2006 benchmark, and the Apache throughput slowdown is only 3 % maximum and negligible on average. In kernel space, it is negligible for SPEC, and 3.8 % for Apache. Both technologies can be deployed in large scale for cloud data centers and server farms in an automated manner.

源语言英语
主期刊名Secure Cloud Computing
出版商Springer New York
303-324
页数22
9781461492788
ISBN(电子版)9781461492788
ISBN(印刷版)1461492777, 9781461492771
DOI
出版状态已出版 - 1 11月 2014

指纹

探究 'Software cruising: A new technology for building concurrent software monitor' 的科研主题。它们共同构成独一无二的指纹。

引用此