クラウド上の仮想マシンの安全なリモート監視機構
全文
(2) 情報処理学会研究報告 IPSJ SIG Technical Report. Vol.2013-OS-126 No.20 2013/8/1. ผͷ VM ʹ IDS ΛΦϑϩʔυ͠ɼVM ͷ֎͔ΒγεςϜͷ ࢹΛߦ͏ɽཧ VM ͳͲͷ IDS Λಈ࡞ͤ͞Δ VM Ͱ Ͱ͖Δ͚ͩଞͷαʔϏεΛఏ͍ͳ͠ڙΑ͏ʹ͢Δ͜ͱͰɼ ߈ܸΛड͚ʹ͘͘͢Δ͜ͱ͕ͰՄೳͰ͋Δɽ͜ΕʹΑΓɼ ҆શʹ IDS Λಈ࡞ͤ͞Δ͜ͱ͕ՄೳͱͳΔɽ ҰํɼΫϥυͷதͰ IDS ΦϑϩʔυΛߦͬͯ IDS ͕ ਖ਼͘͠ಈ࡞͢Δ͜ͱΛอূ͢Δ͜ͱͰ͖ͳ͍ɽΫϥυ ͷཧऀ͕ඞͣ͠৴པͰ͖ΔͱݶΒͳ͍ͨΊͰ͋Δɽ ཧ VM ͷηΩϡϦςΟରࡦ͕ෆेͳ߹ɼ֎෦ͷ߈ܸ. ਤ 1. ऀʹ৵ೖ͞ΕΔڪΕ͕͋Δ্ɼཧऀʹѱҙ͕͋Δ͜ͱ. VM Λ༻͍ͨ IDS Φϑϩʔυ. ߟ͑ΒΕΔɽ͜ͷΑ͏ͳ߹ɼIDS Λఀࢭͤ͞ΒΕͨΓɼ ਖ਼͘͠৵ೖΛݕ͠ͳ͍Α͏ʹվ͟Μ͞ΕͨΓ͢ΔڪΕ. VM ͷཧΛߦ͏ಛݖΛ࣋ͬͨཧ VM ͕༻͍ΒΕΔ͜ͱ. ͕͋Δɽ·ͨɼIDS Λվ͟Μ͠ͳ͘ͱɼIDS ͕ࢹର. ͕ଟ͍͕ɼࢹઐ༻ʹ։ൃ͞ΕͨυϝΠϯ M [4] ͳͲΛ༻. VM ͔Βऔಘ͢ΔσʔλΛվ͟Μ͢Δ͜ͱͰແྗԽ͢Δ͜. ͍Δ͜ͱͰ͖Δɽ͜ͷख๏Λ༻͍Δ͜ͱʹΑΓɼࢹର. ͱߟ͑ΒΕΔɽ. VM ͕߈ܸΛड͚ͨͱͯͦ͠ͷதͰ IDS ͕ಈ࡞ͯ͠. ຊߘͰɼࢹର VM ͕ಈ࡞͍ͯ͠ΔΫϥυͱผ. ͍ͳ͍ͨΊ IDS Λ߈ܸ͞ΕΔڪΕͳ͍ɽҰํɼΦϑϩʔ. ͷϗετʹ IDS ΛΦϑϩʔυ͠ɼωοτϫʔΫܦ༝Ͱ҆શ. υઌͷཧ VM Ͱ IDS Ҏ֎ͷγεςϜΛͰ͖Δ͚ͩಈ. ʹࢹର VM Λ͖ͰࢹΔΑ͏ʹ͢ΔγεςϜ Remote-. ࡞ͤ͞ͳ͍Α͏ʹ͢Δ͜ͱͰɼ߈ܸΛड͚ʹ͘͘͢Δ͜ͱ. Trans ΛఏҊ͢ΔɽRemoteTrans ɼIDS Λ৴པͰ͖Δϗ. ͕Ͱ͖Δɽ. ετ্Ͱಈ࡞ͤ͞Δ͜ͱʹΑΓɼIDS ͕ఀࢭ͞ΕͨΓվ͟. Φϑϩʔυ͞Εͨ IDS ࢹର VM ͷϝϞϦΛղੳ. Μ͞ΕͨΓ͢ΔͷΛ͙͜ͱ͕Ͱ͖Δɽ·ͨɼIDS ͱΫϥ. ͯ͠ใΛऔಘ͢Δ͜ͱͰࢹΛߦ͏ɽྫ͑ɼࢹର. υͷԾϚγϯϞχλʢVMMʣͷؒͰ߹ੑνΣο. VM ʹѱҙͷ͋Δϓϩηε͕ಈ͍͍ͯͳ͍͔Ͳ͏͔Λࢹ. ΫΛߦ͏͜ͱʹΑΓɼཁࢹͨ͠ٻର VM ͷσʔλ͕ਖ਼. ͢ΔʹɼΧʔωϧϝϞϦ্ʹ͋ΔϓϩηεϦετͷઌ಄. ͘͠औಘͰ͖͓ͯΓɼσʔλͷ༰վ͟Μ͞Ε͍ͯͳ͍. ͔ΒϓϩηεใΛॱ൪ʹऔಘ͢Δɽͦͯ͠ɼϓϩηεͷ. ͜ͱΛ֬ೝ͢ΔɽVMM ϦϞʔτΞςεςʔγϣϯͳͲ. ໊લॴ༗ऀͳͲΛνΣοΫͨ͠ΓɼϓϩηεͷϝϞϦ. Λ༻͍Δ͜ͱͰਖ਼͘͠ಈ࡞͢Δ͜ͱΛอূ͢Δɽ. ΛௐͨΓ͢Δ͜ͱͰҟৗͷ༗ແΛࠪ͢ݕΔɽଞʹɼ. զʑ RemoteTrans Λ Xen 4.1.3 [2] ʹ࣮ͨ͠ɽΫϥ. ࢹର VM ͷσΟεΫΛͨࠪ͠ݕΓɼૹड৴͢Δωοτ. υ֎෦ͷࢹϗετͰ RemoteTrans ϥϯλΠϜ͓Αͼ. ϫʔΫύέοτΛղੳ͢Δ IDS Φϑϩʔυ͢Δ͜ͱ͕Ͱ. IDS Λಈ࡞ͤ͞ɼཧ VM ্ͷ RemoteTrans αʔόͱ௨. ͖Δɽ. ৴͢Δɽ·ͨɼTranscall [3] Λ RemoteTrans ʹରԠͤ͞ɼ. IDS Φϑϩʔυख๏ΛΫϥυʹద༻͢Δࡍͷɼ. ࢹϗετ্Ͱ͍͔ͭ͘ͷطଘͷ IDS Λಈ͔͢͜ͱ͕Ͱ͖. Ϋϥυͷཧऀৗʹ৴པͰ͖ΔͱݶΒͳ͍ͱ͍͏͜. ͍ͯΔɽࢹର VM ͷΧʔωϧσʔλ͔Β Shadow proc. ͱͰ͋ΔɽΫϥυ্ͷ VM ϚΠάϨʔγϣϯͰҠಈ͢. ϑΝΠϧγεςϜΛߏங͢Δ࣮ݧΛߦ͍ɼϦϞʔτͷ VM. Δ͜ͱ͕͋ΓɼηΩϡϦςΟҙࣝͷ͍γεςϜཧऀͷ. ͷใΛऔಘͰ͖͍ͯΔ͜ͱɼ௨৴σʔλͷվ͟ΜΛݕ. ͍ΔσʔληϯλͰ VM ͕ಈ࡞͢ΔՄೳੑ͋Δɽ͜ͷΑ. Ͱ͖Δ͜ͱΛ֬ೝͨ͠ɽ·ͨɼσʔλͷऔಘʹैདྷͷΦ. ͏ͳͰڥཧ VM ʹ੬ऑੑ͕͋Δ߹ɼ֎෦͔Βͷ߈ܸ. ϑϩʔυख๏ͷ 15 ഒͷ͕͔͔࣌ؒΔ͜ͱ͕͔ͬͨɽ. ऀʹΑͬͯཧ VM ͷ੍͕ޚୣΘΕΔڪΕ͕͋Δɽ·ͨɼ. ҎԼɼ2 ষͰ IaaS ܕΫϥυͰ IDS ΦϑϩʔυΛߦ͏ ߹ͷʹ͍ͭͯड़ɼ3 ষͰ RemoteTrans ʹ͍ͭ. Ϋϥυཧऀʹѱҙ͕͋ͬͨ߹ɼཧ VM ʹϩάΠϯ ͯ͠༰қʹෆਖ਼Λߦ͏͜ͱ͕Ͱ͖Δɽ. ͯड़Δɽ4 ষͰ࣮ͷৄࡉʹ͍ͭͯड़ɼ5 ষͰ࣮ݧ. ͦͷͨΊɼΦϑϩʔυͨ͠ IDS ͕ਖ਼ৗʹಈ࡞͢Δ͜ͱΛ. ʹ͍ͭͯड़Δɽ6 ষͰؔ࿈͍ͯͭʹڀݚड़ɼ7 ষͰຊ. อূ͢Δ͜ͱͰ͖ͳ͍ɽཧ VM ʹ৵ೖͨ͠߈ܸऀѱ. ߘΛ·ͱΊΔɽ. 2. IaaS ܕΫϥυʹ͓͚Δ IDS Φϑϩʔυ. ҙΛ࣋ͬͨཧऀɼIDS Λఀࢭͤ͞Δ͜ͱͰ৵ೖݕΛ ճආ͢Δ͜ͱ͕Ͱ͖Δɽ·ͨɼIDS Λվ͟Μ͢Δ͜ͱͰɼ ѱҙ͋ΔϓϩηεΛݕग़͠ͳ͍Α͏ʹ͢Δ͜ͱͰ͖Δɽ. IDS Λ҆શʹಈ࡞ͤ͞ΔͨΊʹɼVM Λ༻͍ͨ IDS Φϑ. IDS Λվ͟Μ͠ͳ͘ͱɼIDS ͕ࢹର VM ͷϝϞϦྖ. ϩʔυख๏͕ఏҊ͞Ε͍ͯΔ [1]ɽ͜ͷख๏ɼਤ 1 ͷΑ. ҬΛࢀর͢ΔࡍʹɼࢀরઌΛมߋ͢Δ͚ͩͰɼIDS ͷڍ. ͏ʹࢹରγεςϜ͕ಈ࡞͍ͯ͠Δ VM ͱಉ͡ϗετ. ಈΛม͑ͯແྗԽ͢Δ͜ͱ͕Ͱ͖Δɽ. ্ͷผͷ VM ʹ IDS ΛΦϑϩʔυ͠ɼγεςϜͷ֎ଆ͔. ΫϥυͰ҆શʹ IDS ΦϑϩʔυΛߦ͑ΔΑ͏ʹ͢Δ. Β͢ࢹΔख๏Ͱ͋ΔɽIDS Λಈ࡞ͤ͞Δ VM ͱͯ͠ɼ. ͨΊʹɼSelf-Service CloudʢSSC) [5] ͕ఏҊ͞Ε͍ͯΔɽ. ⓒ 2013 Information Processing Society of Japan. 2.
(3) 情報処理学会研究報告 IPSJ SIG Technical Report. Vol.2013-OS-126 No.20 2013/8/1. SSC ͰɼIDS ΛΦϑϩʔυͨ͠ VM ࢹର VM ͷ ϢʔβͷཧԼʹ͋ΓɼΫϥυͷཧऀͰ͋ͬͯׯব ͢Δ͜ͱ͕Ͱ͖ͳ͍ɽ͔͠͠ɼVMM ʹՃ͑ͯɼ͜ͷ VM ΫϥυͰ৴པ͢Δ෦ͱ͢Δඞཁ͕͋ΔɽVMM ͱ ൺͯɼVM Ͱ OS ΛؚΊͯΑΓෳࡶͳγεςϜ͕ಈ ࡞͍ͯ͠ΔͨΊɼͦͷ੬ऑੑΛ߈ܸ͞ΕΔݥةੑ͕ߴ͘ ͳΔɽ. 3. RemoteTrans ਤ 2 RemoteTrans ͷγεςϜߏ. ຊߘͰɼࢹର VM ͕ಈ࡞͍ͯ͠ΔΫϥυͱผ ͷϗετʹ IDS ΛΦϑϩʔυ͠ɼωοτϫʔΫܦ༝Ͱ҆શ ʹࢹର VM Λ͖ͰࢹΔΑ͏ʹ͢ΔγεςϜ Remote-. Ϛγϯͷϝϯςφϯε࣌ࢹΛܧଓ͢Δ͜ͱ͕Ͱ͖Δɽ. Trans ΛఏҊ͢ΔɽϢʔβ͕ཧ͍ͯ͠Δ৴པͰ͖Δϗε τ্Ͱ IDS Λಈ࡞ͤ͞Δ͜ͱʹΑͬͯɼIDS ͕ఀࢭ͞Ε ͨΓվ͟Μ͞ΕͨΓ͢Δ͜ͱΛ͙͜ͱ͕Ͱ͖ΔɽIDS ͱ. 3.3 VM ͷࢹ RemoteTrans ϥϯλΠϜ͕Ϋϥυͷ RemoteTrans. Ϋϥυͷ VMM ͷؒͰ߹ੑνΣοΫΛߦ͏͜ͱͰɼ. αʔόܦ༝Ͱ VMM ͷ RemoteTrans ϞδϡʔϧʹΞΫ. IDS ͕ࢀর͢Δσʔλͷվ͟ΜΛݕग़͢Δ͜ͱ͕Ͱ͖Δɽ. ηε͢Δ͜ͱʹΑͬͯɼIDS ϦϞʔτͷࢹର VM ͷ ใΛࢀর͢Δ͜ͱ͕Ͱ͖ΔɽIDS ͕ࢹର VM ͷϝϞ. 3.1 ڴҖϞσϧ. ϦσʔλΛࢀর͠Α͏ͱͨ࣌͠ɼͦͷσʔλͷԾΞυϨε. ຊߘͰ֎෦͔Βͷ߈ܸऀѱҙͷ͋ΔΫϥυཧऀ. ͱσʔλαΠζ͔ΒͳΔϦΫΤετΛ RemoteTrans ϥϯλ. ʹΑͬͯཧ VM ͕ѱ༻͞ΕΔ͜ͱΛఆ͍ͯ͠ΔɽIaaS. ΠϜʹૹΔɽRemoteTrans ϥϯλΠϜ͕ϦΫΤετΛωο. ϓϩόΠμࣗମ৴པ͠ɼVMM ϋʔυΣΞΛཧ͢. τϫʔΫܦ༝Ͱ RemoteTrans αʔόʹૹΔͱɼVMM ͷ. Δগͷཧऀ৴པ͢Δɽ͔͠͠ɼཧ VM ͰϢʔβ. RemoteTrans Ϟδϡʔϧ͕ͼݺग़͞ΕΔɽRemoteTrans. VM Λৗతʹཧ͍ͯ͠ΔҰൠͷγεςϜཧऀ৴. ϞδϡʔϧɼϦΫΤετ͞ΕͨԾΞυϨεʹ͋Δσʔ. པ͠ͳ͍ɽ·ͨɼVMM ʹ੬ऑੑͳ͍ͷͱ͠ɼϋʔυ. λΛࢦఆ͞ΕͨαΠζ͚ͩࢹର VM ͷϝϞϦ͔Βऔ. ΣΞʹཧతʹΞΫηε͢Δ߈ܸఆ͠ͳ͍ɽIDS Λ. ಘ͠ɼRemoteTrans αʔόʹฦ͢ɽ͜ͷσʔλɼϨεϙ. Φϑϩʔυ͢ΔϢʔβͷࢹϗετਖ਼͘͠ཧ͞Ε͍ͯ. ϯεͱͯ͠ RemoteTrans ϥϯλΠϜʹฦ͞ΕɼIDS ͕ࢀ. Δͷͱ͠ɼࢹϗετ͕߈ܸΛड͚Δ͜ͱߟ͑ͳ͍ɽ. রͰ͖ΔΑ͏ʹͳΔɽ. RemoteTrans ͰɼVMCrypt [6] ηΩϡΞͳ࣮ߦ 3.2 γεςϜߏ. [ ڥ7] Λ༻͍ͯࢹର VM ͷϝϞϦΛ҉߸Խ͢Δ͜ͱΛ. RemoteTrans Λ༻͍ͯ IDS ΦϑϩʔυΛߦ͏߹ͷγ. ఆ͍ͯ͠ΔͨΊɼVMM Ͱ VM ͷϝϞϦσʔλΛऔ. εςϜߏΛਤ 2 ʹࣔ͢ɽΫϥυ֎ͷࢹϗετ্Ͱ. ಘ͢Δɽ͞ΒʹɼVMM ͷ RemoteTrans Ϟδϡʔϧ. RemoteTrans ϥϯλΠϜΛಈ࡞ͤ͞ɼ͜ͷϥϯλΠϜ্. ϦΫΤετͱϨεϙϯεʹର͢Δվ͟Μͷݕग़ߦ͏ɽ͜. Ͱ IDS Λ࣮ߦ͢ΔɽҰํɼΫϥυͰ RemoteTrans. ͷ߹ੑνΣοΫʹ͍ͭͯ 3.4 અͰड़ɼΫϥυͷ. αʔόΛࢹର VM ͕ಈ࡞͍ͯ͠Δϗετͷཧ VM. VMM Λ৴པ͢ΔͨΊͷख๏ʹ͍ͭͯ 3.5 અͰड़Δɽ. Ͱಈ࡞ͤ͞ΔɽΫϥυͷ VMM Ͱ RemoteTrans Ϟ. VMM Ͱσʔλͷऔಘ͚ͩΛߦ͍ɼσʔλͷૹ৴ߦΘ. δϡʔϧΛಈ࡞ͤ͞ΔɽIDS ͕ࢀর͢Δࢹର VM ͷ. ͳ͍ɽ͜ΕɼRemoteTrans ϥϯλΠϜͱ VMM ͕. ใ RemoteTrans ϥϯλΠϜ͕ RemoteTrans αʔόΛܦ. ௨৴Ͱ͖ΔΑ͏ʹ͢ΔͱɼVMM ͕߈ܸΛड͚ΔՄೳੑ͕. ༝ͯ͠ RemoteTrans ϞδϡʔϧʹΞΫηε͢Δ͜ͱͰऔ. ߴ·ΔͨΊͰ͋ΔɽVMM ͕߈ܸΛड͚ΔͱɼIDS ͕ࢀর. ಘ͢Δɽ. ͢Δσʔλͷ߹ੑνΣοΫΛແޮԽ͞Εͯ͠·͏ڪΕ͕. RemoteTrans ϥϯλΠϜͱ IDS Ϣʔβͷ PC ϓϥ ΠϕʔτɾΫϥυͳͲͷ༷ʑͳ͖Ͱߦ࣮ͰڥΔΑ͏ʹ. ͋Δɽ ཧ VM ্ʹΦϑϩʔυͯ͠ಉҰϗετ্ͷ VM Λ. ͢ΔͨΊʹɼԾΞϓϥΠΞϯεʢVMʣͱͯ͠ఏ͢ڙΔɽ. ࢹ͢ΔΑ͏ʹ։ൃ͞Εͨ IDS ʹ͍ͭͯɼࢹର VM ͷ. VM Ͱಈ࡞ͤ͞Δ͜ͱͷར IDS Λಈ࡞ͤ͞Δࠨʹڥ. σʔλऔಘ෦Λ RemoteTrans ϥϯλΠϜ͕ఏ͢ڙΔ API. ӈ͞Εͳ͍͜ͱͰ͋Δɽ͕ڥมΘΔͱύοέʔδͷՃ. Λ༻͍ͯॻ͖͑Δ͚ͩͰɼϦϞʔτͷ VM Λ͢ࢹΔ͜. IDS ͷॻ͖Ͳͳ͑ΛߦΘͳ͚ΕͳΒͳ͍Մೳੑ͕͋. ͱ͕ՄೳͱͳΔɽ·ͨɼVM Shadow [3] Λ RemoteTrans. Δ͕ɼVM Ͱ͋ΕͲ͜Ͱͦͷ··࣮ߦ͢Δ͜ͱ͕Ͱ͖. ʹରԠͤ͞Δ͜ͱʹΑΓɼطଘͷ IDS Λಈ࡞ͤ͞Δ͜ͱ. Δɽ͞ΒʹɼVM ͷϚΠάϨʔγϣϯΛߦ͏͜ͱͰɼཧ. ՄೳͱͳΔɽVM Shadow ͱɼطଘͷ IDS ʹमਖ਼ΛՃ͑. ⓒ 2013 Information Processing Society of Japan. 3.
(4) 情報処理学会研究報告 IPSJ SIG Technical Report. ਤ 3. Vol.2013-OS-126 No.20 2013/8/1. RemoteTrans ʹରԠͨ͠ VM Shadow ਤ 4 ߹ੑνΣοΫ. 3.5 ϦϓϨΠ߈ܸରࡦ Δ͜ͱͳ͘Φϑϩʔυͯ͠ಈ࡞ͤ͞ΒΕΔΑ͏ʹ͢ΔͨΊ. IDS ͕ࢀর͢ΔσʔλΛվ͟Μ͢Δखஈͱͯ͠ɼϦϓϨ. ͷ࣮ߦ͋ͰڥΔɽਤ 3 ʹ VM Shadow Λ༻͍ͨ߹ͷߏ. Π߈ܸߟ͑ΒΕΔɽϦϓϨΠ߈ܸͱɼҎલʹ௨৴ͨ͠. Λࣔ͢ɽ. ϦΫΤετͱϨεϙϯεΛอଘ͓͖ͯ͠ɼಉ͡ϦΫΤετ ͕ૹΒΕͨ࣌ʹอଘ͓͍ͯͨ͠ϨεϙϯεΛฦ͢߈ܸͰ͋. 3.4 ࢹσʔλͷ߹ੑνΣοΫ. Δɽ߈ܸͷྫͱͯ͠ɼIDS ͕ਖ਼ৗ࣌ͷϓϩηεใΛೖ. RemoteTrans ͷ߈ܸͱͯ͠ɼRemoteTrans ϥϯλΠ. ख͢Δࡍʹɼ߈ܸऀϦΫΤετͱϨεϙϯεͷΛอଘ. Ϝ͔Β RemoteTrans αʔόͷϦΫΤετ͓ΑͼͦͷϨ. ͓ͯ͘͠ɽͦͷޙɼѱҙͷ͋ΔϓϩηεΛࢹର VM Ͱ. εϙϯεͷվ͟Μ͕ߟ͑ΒΕΔɽ௨৴࿏͕҉߸Խ͞Ε͍ͯ. ಈ࡞ͤ͞ɼIDS ͕ϓϩηεใΛೖख͢Δࡍʹɼอଘ͠. ͨͱͯ͠ɼΫϥυͷཧ VM ্Ͱ͜ΕΒͷվ͟Μ͕. ͓͍ͯͨϨεϙϯεΛฦ͢ɽ͜ΕʹΑΓɼIDS ʹਖ਼ৗ࣌ͷ. ߦΘΕΔݥةੑ͕͋Δɽ͠ɼϦΫΤετ͕վ͟Μ͞Εͨ. ϓϩηεใΛࢀরͤ͞Δ͜ͱ͕Ͱ͖Δɽ߈ܸऀϦΫΤ. ߹ɼࢦఆ͞ΕͨԾΞυϨεΛมߋ͠ɼIDS ͕ࢀর͠Α. ετ͞ΕΔΞυϨεͱσʔλαΠζɼ͓ΑͼɼϨεϙϯε. ͏ͱ͍ͯ͠ΔσʔλͱҟͳΔσʔλΛฦͤ͞Δ͜ͱ͕Ͱ. Ͱฦ͞ΕΔσʔλΛվ͟Μ͢Δඞཁ͕ͳ͍ͨΊɼMAC Λ. ͖ͯ͠·͏ɽྫ͑ɼϓϩηεϦετΛͨͲΔͨΊʹ࣍ͷ. ༻͍ͯ͜ͷΑ͏ͳ߈ܸΛݕ͢Δ͜ͱͰ͖ͳ͍ɽ. ϓϩηεͷΞυϨεΛऔಘ͢ΔϦΫΤετ͕ૹΒΕ͖ͯͨ. RemoteTrans ͰɼϦϓϨΠ߈ܸରࡦͱͯ͠ϊϯεͱݺ. ߹ɼ࣍ͷ࣍ͷϓϩηεΛࢦ͢ΞυϨεʹॻ͖͑Δ͜ͱ. ΕΔཚΛؚΊͯ MAC ͷࢉܭΛߦ͏ɽ·ͣɼRemote-. ͕Ͱ͖Δɽ͜ΕʹΑΓѱҙͷ͋ΔϓϩηεͷใΛӅ͞Ε. Trans ϥϯλΠϜΞυϨεͱσʔλαΠζʹՃ͑ͯϊϯ. ͯ͠·͏ڪΕ͕͋Δɽಉ༷ʹɼϨεϙϯεΛվ͟Μ͞ΕΔ. ε RemoteTrans αʔόૹΔɽRemoteTrans Ϟδϡʔ. ͱɼ࣮ࡍͷσʔλͱҟͳΔσʔλΛฦ͢͜ͱ͕Ͱ͖Δɽ. ϧϊϯεؚΊͯϦΫΤετͱऔಘͨ͠σʔλ͔Β MAC. ѱҙͷ͋ΔϓϩηεͷใΛॻ͖͑Δ͜ͱͰɼIDS ʹΑ. Λ͠ࢉܭɼRemoteTrans ϥϯλΠϜʹฦ͢ɽRemoteTrans. ΔݕΛճආ͞Εͯ͠·͏ڪΕ͕͋Δɽ. ϥϯλΠϜอଘ͓͍ͯͨ͠ϊϯεؚΊͯ MAC Λࢉܭ. ͦ͜ͰɼRemoteTrans ͰϦΫΤετ͓ΑͼϨεϙϯε. ͠ɼड৴ͨ͠ MAC ͱൺֱΛߦ͏ɽϊϯεΛ MAC ͷࢉܭ. ͕վ͟Μ͞Ε͍ͯͳ͍͜ͱΛอূ͢ΔͨΊʹɼਤ 4 ͷΑ. ʹؚΊΔ͜ͱʹΑͬͯɼҎલʹ༻ͨ͠ϦΫΤετͱϨε. ͏ʹ߹ੑνΣοΫΛߦ͏ɽVMM ͷ RemoteTrans Ϟ. ϙϯεͷΛ࠶ར༻͢Δ͜ͱͰ͖ͳ͘ͳΓɼϦϓϨΠ߈. δϡʔϧ͕ RemoteTrans ϥϯλΠϜ͔ΒͷϦΫΤετΛ. ܸΛ͙͜ͱ͕Ͱ͖Δɽ. ड͚औΔͱɼϦΫΤετʹ·ؚΕΔԾΞυϨεͱσʔλ αΠζɼͦΕʹࢹ͍ͯͮجର VM ͔Βऔಘͨ͠σʔ. 3.6 VMM ͷશੑνΣοΫ. λ͔ΒϝοηʔδೝূίʔυʢMACʣΛ͢ࢉܭΔɽRe-. RemoteTrans ͰɼΫϥυͰਖ਼͍͠ VMM ͕ಈ࡞. moteTrans αʔό͕औಘͨ͠σʔλͱͱʹ͜ͷ MAC Λ. ͍ͯ͠Δ͜ͱΛ֬ೝ͢ΔͨΊʹɼϦϞʔτΞςεςʔγϣ. ฦ͢ͱɼRemoteTrans ϥϯλΠϜͰอଘ͓͍ͯͨ͠Ξ. ϯΛ༻͍Δɽαʔόͷىಈ࣌ʹ VMM ͷϋογϡΛܭ. υϨεͱσʔλαΠζɼड৴ͨ͠σʔλ͔Β MAC Λࢉܭ. ࢉ͠ɼΫϥυͷ֎ͷ৴པͰ͖Δূݕαʔόʹॺ໊͖. ͠ɼड৴ͨ͠ MAC ͱൺֱΛߦ͏ɽMAC ͕Ұக͠ͳ͚Ε. Ͱૹ৴͢ΔɽϋογϡͷࢉܭλϯύੑϋʔυΣ. ɼϦΫΤετ͔ϨεϙϯεͷͲͪΒ͔͕վ͟Μ͞Εͨ. ΞʢTPM) Λ༻͍ͯߦ͏͜ͱͰɼվ͟ΜΛ͙ɽূݕαʔ. ͱΈͳ͢ɽ߈ܸऀ͕ MAC Λ͍ͳ͖ͰࢉܭΑ͏ʹ͢ΔͨΊ. όॺ໊ͷଥੑΛ֬ೝ͔ͯ͠ΒɼϋογϡΛͯ͠ূݕ. ʹɼMAC ͷ͍༻ʹࢉܭΔݤɼRemoteTrans Ϟδϡʔϧ. VMM ͷશੑΛνΣοΫ͢Δɽىಈ࣌ʹਖ਼͍͠ VMM ͕. ͱ RemoteTrans ϥϯλΠϜ͚ͩͰڞ༗͢Δɽ. ಈ࡞͍ͯ͠Δ͜ͱ͕֬ೝͰ͖ΕɼVMM ͷϝϞϦอػޢ. ⓒ 2013 Information Processing Society of Japan. 4.
(5) 情報処理学会研究報告 IPSJ SIG Technical Report. ೳʹΑΓ࣮ߦ࣌ͷ VMM ͷվ͟Μ͙͜ͱ͕Ͱ͖Δɽ. Vol.2013-OS-126 No.20 2013/8/1. ༷ͱͳ͍ͬͯΔ͕ɼࡏݱͷ࣮ͰࣄલʹݤΛڞ༗ͯ͠ ͍Δɽ. 3.7 ݤཧ RemoteTrans ͰɼMAC Λ͢ࢉܭΔͱ͖ʹ༻͍Δڞ༗. 4.2 RemoteTrans αʔό. ݤΛ RemoteTrans ϥϯλΠϜͱ VMM ͷ RemoteTrans. RemoteTrans αʔόɼRemoteTrans ϥϯλΠϜ͔ΒϦ. ϞδϡʔϧͷؒͰ҆શʹڞ༗͢ΔɽRemoteTrans ϥϯλ. ΫΤετΛड͚ͱ͔ͬͯΒɼϋΠύʔίʔϧΛ༻͍ͯ VMM. ΠϜ͕ RemoteTrans αʔόʹΞΫηε͢Δࡍʹଓઌͷ. ͷ RemoteTrans Ϟδϡʔϧʹड৴ͨ͠ϦΫΤετΛૹ. VMM ͷެ։ݤΛݤαʔό͔Βऔಘ͢Δɽ͜ͷݤαʔό. ΔɽRemoteTrans ϞδϡʔϧͰ·ͣɼड͚औͬͨԾΞ. ৴པͰ͖Δͷͱ͠ɼ͋Β͔͡Ίਖ਼ͳ VMM ͷެ։. υϨεΛϚγϯϝϞϦͷϑϨʔϜ൪߸ʢMFNʣʹม͢Δɽ. ొ͕ݤ͞Ε͍ͯΔͷͱ͢ΔɽRemoteTrans ϥϯλΠ. rt get data ͔ؔΒͷϦΫΤετͷ߹ɼΧʔωϧͷϖʔ. ϜͰੜͨ͠ڞ༗ݤΛ VMM ͷެ։ݤΛ༻͍ͯ҉߸Խ͠ɼ. δςʔϒϧΛͨͲΔ͜ͱͰมΛߦ͏ɽrt get proc data. RemoteTrans αʔόʹૹΔɽRemoteTrans αʔό҉߸. ͔ؔΒͷϦΫΤετͷ߹ɼPGD ͕ࢦ͢ϓϩηεͷϖʔ. Խ͞Εͨެ։ݤΛ RemoteTrans ϞδϡʔϧʹૹΓɼVMM. δςʔϒϧΛͨͲΔ͜ͱͰมΛߦ͏ɽ࣍ʹɼ͚ͨͭݟ. ʹ͋ΔൿີݤΛ༻͍ͯ෮߸Խ͢Δ͜ͱͰ IDS ͷ࣮ߦ͝ͱʹ. MFN ͕ࢦ͢ϝϞϦϖʔδΛϚοϓͯ͠ඞཁͳσʔλΛऔ. ҟͳΔڞ༗ݤΛ͏ɽVMM ͷൿີݤ TPM Λ༻͍ͯ෧. ಘ͢ΔɽϦΫΤετ͞Εͨσʔλ͕ϖʔδڥքʹ·͕ͨΔ. ҹʢ҉߸Խʣ͓ͯ͘͜͠ͱͰɼਖ਼͍͠ VMM ͕ىಈͨ͠ͱ. ߹ɼ࿈ଓ͢ΔϖʔδͷσʔλΛϚοϓ͠σʔλΛऔಘ. ͖͚ͩ෧ҹΛղআʢ෮߸Խʣ͢Δ͜ͱ͕Ͱ͖Δɽ. ͢Δɽ. 4. ࣮. ͦͷޙɼϦΫΤετͱऔಘͨ͠σʔλ͔Β MAC Λ͢ࢉܭ ΔɽMAC ͷࢉܭϋογϡؔͷ SHA-1 Λ༻͍ΔɽRe-. զʑ RemoteTrans Λ Xen 4.1.3 ʹ࣮ͨ͠ɽಛݖΛ. moteTrans Ϟδϡʔϧ͕औಘͨ͠σʔλͱ ͨ͠ࢉܭMAC. ͍࣋ͬͯΔ VM Ͱ͋ΔυϝΠϯ 0 Ͱ RemoteTrans αʔό. Λ RemoteTrans αʔόʹฦ͢ͱɼRemoteTrans αʔό. Λಈ࡞ͤ͞ɼ௨ৗͷ VM Ͱ͋ΔυϝΠϯ U Λࢹର VM. ͦΕΛϨεϙϯεͱͯ͠ RemoteTrans ϥϯλΠϜʹૹ৴. ͱͨ͠ɽࢹର VM ͷ OS ͱͯ͠ Linux 2.6.27.35 Λ༻. ͢Δɽ. ͍ͨɽ. 4.3 Transcall ͷ RemoteTrans ରԠ 4.1 RemoteTrans ϥϯλΠϜ. Transcall ɼطଘͷ IDS ΛΦϑϩʔυ͢ΔͨΊͷ࣮ߦ. RemoteTrans ϥϯλΠϜͰɼϦϞʔτͷ VM ͔Βσʔ. ڥVM Shadow Λఏ͢ڙΔγεςϜͰ͋ΔɽTranscall ͷ. λΛऔಘ͢ΔͨΊʹ rt get data ؔͱ rt get proc data ؔ. ߏΛਤ 5 ʹࣔ͢ɽTranscall γεςϜίʔϧɾΤϛϡ. Λఏ͢ڙΔɽ. Ϩʔλͱ Shadow ϑΝΠϧγεςϜͰߏ͞ΕΔɽγες ϜίʔϧɾΤϛϡϨʔλʹΑͬͯ VM Shadow ͷதͰಈ. rt get data ࢹର VM ͷΧʔωϧσʔλΛࢀর͢Δ ͱ͖ʹͼݺग़͢ɽҾͱͯ͠ԾΞυϨεɼσʔλα. ࡞͢Δϓϩηε͕ൃߦ͢ΔγεςϜίʔϧΛΤϛϡϨʔ τ͠ɼࢹର VM ͷΧʔωϧͷใΛฦ͢ɽͨͩ͠ɼ. ΠζΛऔΓɼऔಘͨ͠σʔλΛ֬อͨ͠ϝϞϦʹ֨ೲ. Φϑϩʔυઌ VM ͷػೳΛར༻Ͱ͖ΔϝϞϦཧͳͲͷ. ͠ɼͦͷΞυϨεΛฦ͢ɽ. γεςϜίʔϧɼͦͷ VM ͷ OS ʹରͯ͠ൃߦ͢Δɽ. rt get proc data ࢹର VM ͷதͷϓϩηεͷΧʔ. Shadow ϑΝΠϧγεςϜ Transcall ࣮ߦ࣌ʹࢹର. ωϧσʔλΛࢀর͢Δͱ͖ʹͼݺग़͢ɽྫ͑ɼϓϩ. VM ͷσΟεΫΠϝʔδΛΦϑϩʔυઌ VM ʹϚϯτ͢. ηεΛىಈͨ͠ͱ͖ͷίϚϯυϥΠϯϓϩηεͷϝ. ΔɽͦΕʹΑΓɼࢹର VM ͰΘΕ͍ͯΔͷͱಉ͡. ϞϦ্ʹ֨ೲ͞Ε͍ͯΔɽ͜ͷؔԾΞυϨεͱ. ϑΝΠϧγεςϜΛఏ͢ڙΔɽ·ͨɼಛघͳϑΝΠϧγε. σʔλαΠζʹՃ͑ͯɼϓϩηεͷϖʔδάϩʔόϧ. ςϜͱͯ͠ Shadow proc ϑΝΠϧγεςϜఏ͢ڙΔɽ͜. σΟϨΫτϦʢPGD) ͷԾΞυϨεΛҾʹऔΓɼ. ͷϑΝΠϧγεςϜࢹର VM ͷ proc ϑΝΠϧγε. औಘͨ͠σʔλ͕֨ೲ͞ΕͨϝϞϦͷΞυϨεΛฦ͢ɽ. ςϜͷใΛఏ͠ڙɼΧʔωϧͷࡏݱͷঢ়ଶߦ࣮ࡏݱத ͷϓϩηεใͳͲΛؚΜͰ͍Δɽྫ͑ɼps ίϚϯυ. RemoteTrans αʔόʹϦΫΤετΛૹΔࡍʹɼϊϯε. netstat ίϚϯυ proc ϑΝΠϧγεςϜΛࢀর࣮ͯ͠ߦ. ͱͯ͠ੜͨ͠ཚҰॹʹૹ৴͢ΔɽϨεϙϯε͕ฦ͞. ͞ΕΔɽTranscall Ͱɼࢹର VM ͷΧʔωϧϝϞϦ. ΕΔͱ MAC ͷূݕΛߦ͍ɼड৴ͨ͠ MAC ͷͱҟͳΔ. ͔ΒใΛऔಘ͢Δ͜ͱͰ proc ϑΝΠϧγεςϜͷ. ߹ؔͷฦΓͱͯ͠ NULL Λฦ͢ɽ. ใΛऔಘ͢Δɽ. ͜ΕΒͷؔΛ࠷ॳʹͼݺग़ͨ࣌͠ʹɼRemoteTrans. Transcall Λ RemoteTrans ʹରԠͤ͞ɼࢹର VM ͷ. αʔόʹଓ͢Δɽͦͷࡍʹ 3.7 અͷΑ͏ʹڞ༗ݤΛૹΔ. proc ϑΝΠϧγεςϜΛωοτϫʔΫܦ༝ͰऔಘͰ͖ΔΑ. ⓒ 2013 Information Processing Society of Japan. 5.
(6) 情報処理学会研究報告 IPSJ SIG Technical Report. Vol.2013-OS-126 No.20 2013/8/1 ද 1. Shadow proc ϑΝΠϧγεςϜߏங࣌ؒʢඵʣ ࣮ߦ࣌ؒ ैདྷγεςϜ. 1.1. RemoteTrans. 16.4. ਤ 5 Transcall ͷγεςϜߏ. ͏ʹͨ͠ɽզʑϦϞʔτͷϗετʹطଘͷ IDS ΛΦϑ ϩʔυͰ͖ΔΑ͏ʹ͢Δ͜ͱΛඪͱ͍ͯ͠Δɽࡏݱͷͱ ͜ΖɼγεςϜίʔϧɾΤϛϡϨʔλͱ Shadow proc ϑΝ ΠϧγεςϜΛ RemoteTrans ϥϯλΠϜ্Ͱ࣮ߦͰ͖ɼ ࢹର VM ͷ proc ϑΝΠϧγεςϜΛωοτϫʔΫܦ༝ Ͱऔಘ͢Δ͜ͱ͕Ͱ͖͍ͯΔɽͦͷͨΊʹɼࢹର VM. ਤ 6. RemoteTrans ͷ࣮ߦ࣌ؒͷ༁ʢඵʣ. ͷϝϞϦΛࢀর͍ͯ͠Δ෦Λ RemoteTrans ͕ఏ͢ڙΔ. API Λ༻͍ͯॻ͖ͨ͑ɽࢹର VM ͷԾσΟεΫ ΛࢀরͰ͖ΔΑ͏ʹ͢Δ͜ͱࠓޙͷ՝Ͱ͋Δɽ. 5. ࣮ݧ ·ͣɼRemoteTrans ʹΑΓϦΫΤετ͓ΑͼϨεϙϯ εͷվ͟Μ͕ݕग़Ͱ͖Δ͜ͱΛ֬ೝ͢Δ࣮ݧΛߦͬͨɽ࣍. 5.2 ϦϓϨΠ߈ܸݕ ϦϓϨΠ߈ܸΛݕͰ͖Δ͜ͱΛ֬ೝ͢Δ࣮ݧΛߦͬͨɽ ϦϓϨΠ߈ܸͱͯ͠ɼҎલʹฦ͞ΕͨϨεϙϯεΛอଘ͠ ͓͖ͯɼͦͰޙΕΛ RemoteTrans ϥϯλΠϜʹฦ͢Α͏ ʹͨ͠ɽ࣮ݧͷ݁ՌɼMAC ͕ҰகͤͣɼϦϓϨΠ߈ܸʹ ͓͍ͯϨεϙϯεͷվ͟ΜΛݕ͢Δ͜ͱ͕Ͱ͖ͨɽ. ʹɼRemoteTrans Λ༻͍ͯϦϞʔτͷࢹର VM ͷ proc ϑΝΠϧγεςϜͷใΛऔಘ͠ɼShadow proc ϑΝΠϧ. 5.3 طଘͷ IDS ͷಈ࡞֬ೝ. γεςϜΛߏங͢Δͷʹ͔͔Δ࣌ؒΛଌఆͨ͠ɽࢹର. RemoteTrans ʹରԠͨ͠ VM Shadow Λ༻͍ͯɼطଘ. ϗετʹ Intel Core i7 ͷ CPUɼ16GB ͷϝϞϦΛࡌ. ͷ IDS ͕ಈ࡞͢Δ͜ͱΛ֬ೝ͢Δ࣮ݧΛߦͬͨɽShadow. ͨ͠ϚγϯΛ༻͠ɼVMM ͱͯ͠ Xen 4.1.3 Λಈ࡞ͤ͞. proc ϑΝΠϧγεςϜΛࢀর͢Δ ps ͱ netstat ίϚϯυ. ͨɽRemoteTrans αʔόΛಈ࡞ͤ͞ΔυϝΠϯ 0 OS ʹ. ͷಈ࡞֬ೝΛߦͬͨͱ͜ΖɼͦΕͧΕࢹର VM ͷ࣮ߦ. Linux 3.2.0ɼࢹର VM ͷ OS ʹ Linux 2.6.27.35 Λ. ݁ՌΛฦ͢͜ͱΛ֬ೝͨ͠ɽͨͩ͠ɼnetstat ͷ࣮ߦ݁Ռ. ༻͍ͨɽRemoteTrans ϥϯλΠϜΛಈ࡞ͤ͞Δࢹϗετ. ͷҰ෦͕ਖ਼͘͠औಘͰ͖͍ͯͳ͔ͬͨɽ. ʹɼIntel Core i7 ͷ CPUɼ8GB ͷϝϞϦΛࡌͨ͠Ϛ γϯΛ༻͠ɼOS ʹ Linux 3.2.0 Λ༻͍ͨɽ͜ΕΒͷϗ ετΪΨϏοτΠʔαωοτɾεΠονͰଓͨ͠ɽ. 5.4 Shadow proc ϑΝΠϧγεςϜߏங࣌ؒ Shadow proc ϑΝΠϧγεςϜͷߏஙʹ͔͔Δ࣌ؒΛै དྷγεςϜͱ RemoteTrans Λ༻͍ͨγεςϜͱͰൺֱ͠. 5.1 ϦΫΤετ͓ΑͼϨεϙϯεͷվ͟Μݕ RemoteTrans ʹ͓͚ΔϦΫΤετͱϨεϙϯεͷվ͟ Μ͕ݕͰ͖Δ͔Ͳ͏͔Λ֬ೝ͢Δ࣮ݧΛߦͬͨɽͦͷͨ. ͨɽ࣮݁ݧՌΛද 1 ʹࣔ͢ɽRemoteTrans Λ༻͍ͨγε ςϜͰɼैདྷγεςϜͷ 15 ഒఔͷ͕͔͔࣌ؒͬͯ͠ ·͍ͬͯΔ͜ͱ͕Θ͔Δɽ. ΊʹɼRemoteTrans αʔόʹૹΒΕͯ͘ΔϦΫΤετͱ. ࣍ʹɼߏஙʹ͓͚ΔϘτϧωοΫΛௐΔͨΊʹ࣮ߦ࣌. RemoteTrans ϥϯλΠϜฦ͢Ϩεϙϯεͷվ͟ΜΛߦͬ. ؒͷ༁ΛௐͨɽRemoteTrans Λ༻͍ͨߏஙͷࡍʹɼ. ͨɽ۩ମతʹɼಛఆͷϓϩηεใΛ࣋ͭΞυϨε͕ૹ. σʔλ௨৴ɼϋΠύʔίʔϧΛ༻͍ͨ VMM Ͱͷσʔλ. ΒΕ͖ͯͨ࣌ʹϦΫΤετʹ·ؚΕΔԾΞυϨεͱσʔ. औಘ͓Αͼ MAC ͷࢉܭɼRemoteTrans ϥϯλΠϜ্Ͱ. λαΠζɼϨεϙϯεʹ·ؚΕΔσʔλͷվ͟ΜΛͦΕͧ. ͷ MAC ͷߦ͕ͲͳূݕΘΕΔɽ࣮݁ݧՌΛਤ 6 ʹࣔ͢ɽ. ΕߦͬͨɽRemoteTrans Λ༻͍ͯ proc ϑΝΠϧγεςϜ. ͜ͷ݁ՌΑΓɼ௨৴ʹ 10.5 ඵ͔͔͓ͬͯΓɼ࣮ߦ࣌ؒͷ. ͷऔಘΛߦ͓͏ͱͨ͠ͱ͜ΖɼMAC ͕ҰகͤͣɼϦΫΤ. 64%ΛΊ͍ͯΔ͜ͱ͕Θ͔ͬͨɽShadow proc ϑΝΠϧ. ετ·ͨϨεϙϯε͕վ͟Μ͞Ε͍ͯΔ͜ͱΛݕ͢Δ. γεςϜΛߏங͢ΔͨΊʹσʔλૹड৴ 34210 ճߦΘΕ. ͜ͱ͕Ͱ͖ͨɽ. ͍ͯͨɽ. ⓒ 2013 Information Processing Society of Japan. 6.
(7) 情報処理学会研究報告 IPSJ SIG Technical Report. 6. ؔ࿈ڀݚ Self-Service CloudʢSSC) [5] ɼΫϥυͷϢʔβ͚ͩ ʹࣗͷ VM Λཧ͢ΔݶݖΛ༩͑ɼΫϥυͷཧऀ ͔ΒͷׯবΛ͙ɽϢʔβαʔϏευϝΠϯͱݺΕΔ. Vol.2013-OS-126 No.20 2013/8/1. σʔλΛ෮߸Խ͢Δ͜ͱͰɼΦϑϩʔυͨ͠ IDS ͷ࣮ߦ͕ ՄೳʹͳΔɽ. 7. ·ͱΊ ຊߘͰɼࢹର VM ͕ಈ࡞͍ͯ͠ΔΫϥυͱ. VM Λ҆શʹىಈ͠ɼଞͷ VM Λ͢ࢹΔ͜ͱ͕Ͱ͖Δɽ. ผͷϗετʹ IDS ΛΦϑϩʔυ͠ɼωοτϫʔΫܦ༝Ͱ. Ϋϥυͷཧऀ͕αʔϏευϝΠϯͷதͷ IDS Λఀࢭ͠. ҆શʹࢹର VM Λ͖ͰࢹΔΑ͏ʹ͢ΔγεςϜ Re-. ͨΓվ͟Μͨ͠Γ͢Δ͜ͱͰ͖ͳ͍ɽ͔͠͠ɼαʔϏε. moteTrans ΛఏҊͨ͠ɽRemoteTrans IDS Λ৴པͰ͖. υϝΠϯͷγεςϜʹ੬ऑੑ͕͋Δͱ߈ܸΛड͚ΔՄೳ. Δϗετ্Ͱಈ࡞ͤ͞Δ͜ͱʹΑΓɼIDS ͷఀࢭɾվ͟. ੑ͕͋Δɽ. ΜΛ͙ɽ·ͨɼIDS ͱΫϥυͷ VMM ͷؒͰ߹. CloudVisor [8] VMM ͷԼʹηΩϡϦςΟϞχλΛಋ. ੑνΣοΫΛߦ͏͜ͱͰɼࢀর͢Δσʔλͷվ͟ΜΛݕ. ೖ͢Δ͜ͱͰɼVMM ؚΊͯ৴པͰ͖ͳ͍Ϋϥυͷத. ग़͢ΔɽRemoteTrans Λ Xen ʹ࣮͠ɼϦΫΤετ͓Α. Ͱ҆શʹ VM Λಈ࡞ͤ͞Δ͜ͱ͕Ͱ͖ΔɽVM ͕ଞͷ. ͼϨεϙϯεͷվ͟ΜΛݕͰ͖Δ͜ͱΛ֬ೝͨ͠ɽ·. VM Λ͢ࢹΔػೳఏ͞ڙΕ͓ͯΒͣɼཧ VM ͕ VM. ͨɼTranscall Λ RemoteTrans ʹରԠͤ͞Δ͜ͱͰɼطଘ. ͷϝϞϦΛࢀর͢Δ࣌ʹ҉߸Խ͞ΕΔͨΊɼIDS ΛΦϑ. ͷ IDS Λಈ࡞ͤ͞ΒΕΔΑ͏ʹͨ͠ɽ. ϩʔυ͢Δ͜ͱͰ͖ͳ͍ɽ. ࠓޙͷ՝σʔλऔಘͷߴԽͰ͋ΔɽࡏݱҰͭͣ. Copilot [9] Χʔωϧͷ߹ੑΛϦϞʔτ͔ΒνΣοΫ. ͭσʔλΛϦΫΤετͯ͠औಘ͍ͯ͠Δ͕ɼҰׅͯ͠औಘ. Ͱ͖ΔγεςϜͰ͋ΔɽPCI ΧʔυΛ༻͍ͯϦϞʔτϗε. Ͱ͖ΔΑ͏ʹ͢Δํ๏͕ߟ͑ΒΕΔɽྫ͑ɼ̍ճͷϦΫ. τʹΧʔωϧϝϞϦΛૹΓɼΧʔωϧͷվ͟ΜΛݕग़͢Δ. ΤετͰϓϩηεϦετΛͨͲͬͯͯ͢ͷϓϩηεσʔ. ͜ͱ͕Ͱ͖Δɽ͔͠͠ɼΫϥυͷͯ͢ͷϗετʹઐ. λΛऔಘ͢Εɼ௨৴ճΛେ෯ʹ͖ͰݮΔɽ·ͨɼϝ. ༻ͷ PCI ΧʔυΛಋೖ͢Δͷ࣮ݱతͰͳ͍ɽ. ϞϦσʔλ͚ͩͰͳ͘ɼσΟεΫσʔλΛऔಘͰ͖ΔΑ͏. HyperCheck [10] CPU ͷ҆શͳϞʔυͰ͋Δ SMM. ʹ͢Δ͜ͱ՝ͷҰͭͰ͋ΔɽσΟεΫσʔλϝϞϦ. Λͬͯ VMM ͷϝϞϦΛϦϞʔτϗετʹૹΓɼશੑ. σʔλͱൺͯڊେͰ͋ΔͨΊɼ௨৴ྔΛݮΒ͕͢ඞ. ͷνΣοΫΛߦ͏γεςϜͰ͋ΔɽϝϞϦΛ҆શʹϦϞʔ. ਢͰ͋Δɽ. τϗετʹૹΔ͜ͱ͕Ͱ͖ΔͰ RemoteTrans ʹࣅ͍ͯ Δɽ͔͠͠ɼSMM ্ͷίʔυϦϞʔτϗετ͔ΒͷϦ. ࢀߟจݙ. ΫΤετΛड͚औΔ͜ͱ͕Ͱ͖ͳ͍ͨΊɼఆظతʹϝϞϦ. [1]. શମΛૹ৴͢Δඞཁ͕͋ΔɽͦͷͨΊɼσʔλ௨৴ྔ͕ଟ ͘ͳΔͱ͍͏͕͋Δɽ. HyperGuard [11]ɼHyperSentry [12]ɼFlicker [13]ɼSPE. [2]. Observer [14] ɼϋʔυΣΞͷػೳΛ༻͍Δ͜ͱʹΑͬ ͯΫϥυͰ҆શʹ IDS Λಈ࡞ͤ͞Δ͜ͱ͕Ͱ͖Δɽ. HyperGuard SMM ্Ͱ VMM ͷϝϞϦνΣοΫΛߦ ͏ɽHyperSentry SMM Λར༻ͯ͠ VMM ͷ IDS Λ. [3]. ҆શʹ࣮ߦ͢ΔɽFlicker Intel TXT AMD SVM Λ༻. [4]. ͍ͯ҆શʹ IDS Λ࣮ߦ͢ΔɽSPE Observer Cell/B.E. ͷ Isolation ϞʔυΛ༻͍ͯ SPE ্Ͱ҆શʹ IDS Λ࣮ߦ͢. [5]. Δɽ͔͠͠ɼࢹதʹγεςϜͷଞͷ෦Λఀࢭͤ͞ͳ͚ ΕͳΒͳ͔ͬͨΓɼҰൠతͰͳ͍ϋʔυΣΞ͕ඞཁͱ ͳͬͨΓ͢Δɽ. [6]. ηΩϡΞͳ࣮ߦ[ ڥ7] VMCrypt [6] VM ͷϝϞ ϦϨδελ͔Βཧ VM ใ͕࿙Ӯ͢Δ͜ͱΛ͙ γεςϜͰ͋Δɽཧ VM ͕Ϣʔβ VM ͷϝϞϦΛϚο. [7]. ϓ͠Α͏ͱ͢ΔͱɼVMM ͕ͦͷϝϞϦ༰Λ҉߸Խ͢ Δɽ·ͨɼVM ͷϝϞϦͷվ͟Μݕग़͢Δ͜ͱ͕Ͱ͖Δɽ ͜ΕΒͷߏػΛ༻͍ΔͱϝϞϦ͕҉߸Խ͞ΕΔͨΊɼै དྷͷ IDS ΦϑϩʔυͰࢹΛߦ͏͜ͱ͕Ͱ͖ͳ͘ͳΔɽ. RemoteTrans Λ༻͍ΕϦϞʔτͷࢹϗετͰϝϞϦ ⓒ 2013 Information Processing Society of Japan. [8]. Garfinkel, T. and Rosenblum, M.: A Virtual Machine Introspection Based Architecture for Intrusion Detection, Proceedings of Network and Distributed Systems Security Symposium, pp. 191–206 (2003). Barham, P., Dragovic, B., Fraser, K., Hand, S., Harris, T., Ho, A., Neugebauer, R., Pratt, I. and Warfield, A.: Xen and the art of virtualization, Proceedings of the nineteenth ACM symposium on Operating systems principles, pp. 164–177 (2003). ൧ాوେɼޫདྷ݈ҰɿVM Shadowɿطଘ IDS ΛΦϑϩʔ υ͢ΔͨΊͷ࣮ߦڥɼୈ 119 ճ OS ڀݚձ (2011). Ӊٶणਔɼޫདྷ݈ҰɿVM ϚΠάϨʔγϣϯΛՄೳʹ ͢Δ IDS Φϑϩʔυߏػɼୈ 28 ճຊιϑτΣΞՊ ֶձେձ (2011). Butt, S., Lagar-Cavilla, H. A., Srivastava, A. and Ganapathy, V.: Self-service cloud computing, Proceedings of the 2012 ACM conference on Computer and communications security, pp. 253–264 (2012). Tadokoro, H., Kourai, K. and Chiba, S.: Preventing Information Leakage from Virtual Machines’ Memory in IaaS Clouds, IPSJ Transactions on Advanced Computing Systems, Vol. 5, No. 4, pp. 101–111 (2012). Li, C., Raghunathan, A. and Jha, N. K.: Secure Virtual Machine Execution under an Untrusted Management OS, Proceedings of IEEE CLOUD’10, pp. 172–179 (2010). Zhang, F., Chen, J., Chen, H. and Zang, B.: CloudVisor: retrofitting protection of virtual machines in multitenant cloud with nested virtualization, Proceedings of. 7.
(8) 情報処理学会研究報告 IPSJ SIG Technical Report. [9]. [10]. [11] [12]. [13]. [14]. Vol.2013-OS-126 No.20 2013/8/1. the Twenty-Third ACM Symposium on Operating Systems Principles, pp. 203–216 (2011). Petroni, Jr., N. L., Fraser, T., Molina, J. and Arbaugh, W. A.: Copilot - a coprocessor-based kernel runtime integrity monitor, Proceedings of the 13th conference on USENIX Security Symposium, pp. 13–13 (2004). Wang, J., Stavrou, A. and Ghosh, A.: HyperCheck: A Hardware-Assisted Integrity Monitor, Proceedings of International Symposium of Recent Advances in Intrusion Detection, pp. 158–177 (2010). Rutkowska, J., Wojtczuk, R. and Tereshkin, A.: Xen 0wning Trilogy, Black Hat USA (2008). Azab, A. M., Ning, P., Wang, Z., Jiang, X., Zhang, X. and Skalsky, N. C.: HyperSentry: enabling stealthy incontext measurement of hypervisor integrity, Proceedings of the 17th ACM conference on Computer and communications security, pp. 38–49 (2010). McCune, J. M., Parno, B., Perrig, A., Reiter, M. K. and Isozaki, H.: Flicker: An Execution Infrastructure for TCB Minimization, Proceedings of European Conference of Computer Systems, pp. 315–328 (2008). Kourai, K. and Nagata, T.: A Secure Framework for Monitoring Operating Systems Using SPEs in Cell/B.E., Proceedings of Pacific Rim International Symposium on Dependable Computing, pp. 41–50 (2012).. ⓒ 2013 Information Processing Society of Japan. 8.
(9)
関連したドキュメント
[r]
In this paper, we propose the column-parallel LoS detection architecture for the integrated image sensor, which has a capability to track the saccade, as well as its implementation
The VLSI architecture is characterized by pipeline processing of the divided images, concurrent motion models estimation for multiple regions, and a common processing element
Shapiro, The Foreign Intelligence Surveillance Act: Legislative Balancing of national Security and the Fourth Amendment, 15 HARV.. to Study Governmental Operations with Respect
はじめに 本報告書は、原子力安全監視室(以下、「NSOO」)の 2017 年度第 4 四半期(1~3
3. 利用者の安全確保のための遊歩道や案内板などの点検、 応急補修 4. 動植物の生息、 生育状況など自然環境の継続的観測および監視
全体構想において、施設整備については、良好
安全性は日々 向上すべきもの との認識不足 安全性は日々 向上すべきもの との認識不足 安全性は日々 向上すべきもの との認識不足 他社の運転.