Papers

May 1, 2016

Evaluation and design of function for tracing diffusion of classified information for file operations with KVM

Journal of Supercomputing
  • Shota Fujii
  • ,
  • Masaya Sato
  • ,
  • Toshihiro Yamauchi
  • ,
  • Hideo Taniguchi

Volume
72
Number
5
First page
1841
Last page
1861
Language
English
Publishing type
Research paper (scientific journal)
DOI
10.1007/s11227-016-1671-5
Publisher
SPRINGER

© 2016, Springer Science+Business Media New York. Cases of classified information leakage have become increasingly common. To address this problem, we have proposed a function for tracing the diffusion of classified information within an operating system. However, this function suffers from the following two problems: first, in order to introduce the function, the operating system’s source code must be modified. Second, there is a risk that the function will be disabled when the operating system is attacked. Thus, we have designed a function for tracing the diffusion of classified information in a guest operating system by using a virtual machine monitor. By using a virtual machine monitor, we can introduce the proposed function in various environments without modifying the operating system’s source code. In addition, attacks aimed at the proposed function are made more difficult, because the virtual machine monitor is isolated from the operating system. In this paper, we describe the implementation of the proposed function for file operations and child process creation in the guest operating system with a kernel-based virtual machine. Further, we demonstrate the traceability of diffusing classified information by file operations and child process creation. We also report the logical lines of code required to introduce the proposed function and performance overheads.

Link information
DOI
https://doi.org/10.1007/s11227-016-1671-5
DBLP
https://dblp.uni-trier.de/rec/journals/tjs/FujiiSYT16
Web of Science
https://gateway.webofknowledge.com/gateway/Gateway.cgi?GWVersion=2&SrcAuth=JSTA_CEL&SrcApp=J_Gate_JST&DestLinkType=FullRecord&KeyUT=WOS:000374967100011&DestApp=WOS_CPL
URL
https://dblp.uni-trier.de/db/journals/tjs/tjs72.html#FujiiSYT16
Scopus
https://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=84959178114&origin=inward
Scopus Citedby
https://www.scopus.com/inward/citedby.uri?partnerID=HzOxMe3b&scp=84959178114&origin=inward
ID information
  • DOI : 10.1007/s11227-016-1671-5
  • ISSN : 0920-8542
  • eISSN : 1573-0484
  • DBLP ID : journals/tjs/FujiiSYT16
  • SCOPUS ID : 84959178114
  • Web of Science ID : WOS:000374967100011

Export
BibTeX RIS