Treffer: Time Capsule: Secure Recording of Accesses to a Protected Datastore

Title:
Time Capsule: Secure Recording of Accesses to a Protected Datastore
Contributors:
The Pennsylvania State University CiteSeerX Archives
Publication Year:
2009
Collection:
CiteSeerX
Document Type:
Fachzeitschrift text
File Description:
application/pdf
Language:
English
Rights:
Metadata may be used without restrictions as long as the oai identifier remains attached to it.
Accession Number:
edsbas.262FF47E
Database:
BASE

Weitere Informationen

We present an approach for transparently recording accesses to protected storage. In particular, we provide a framework for data monitoring in a virtualized environment using only the abstractions exposed by the hypervisor. To achieve our goals, we explore techniques for efficiently harvesting ap-plication code pages resident in memory at the time disk operations hit the I/O ring, and subsequently apply novel heuristics to overcome the “semantic gap ” issue between file-system objects and disk blocks. Our forensic layer records all transactions in a version-based audit log that allows for faithful reconstruction of accesses to the datastore over time. We provide an empirical evaluation of our design that shows our approach to be promising, and very accurate in mapping application to block level access patterns—even under very noisy conditions.