With the development of cloud computing, virtualization technology has been widely used in our life. Meanwhile, it became one of the key targets for some attackers. The integrity measurement in virtual machine has become an urgent problem. Some of the existing virtualization platform integrity measurement mechanism introduces the trusted computing technology, according to a trusted chain that the Trusted Platform Module (TPM) established for trusted root to measure the integrity of process in static. But this single chain static measurement cannot ensure the dynamic credible in platform running. To solve the problem that the virtual trusted platform can not guarantee the dynamic credibility, this paper put forward Dynamic Integrity Measurement Model (DIMM) based on virtual Trusted Platform Module (vTPM) which had been implemented with typical virtual machine monitor Xen as an example. DIMM combined with virtual machine introspection and event capture technology to ensure the security of the entire user domain. Based on the framework, this paper put forward Self-modify dynamic measurement strategy which can effectively reduce the measurement frequency and improve the measurement performance. Finally, it is proved that the validity and feasibility of the proposed model with comparison experiments.
[1]
Trent Jaeger,et al.
Design and Implementation of a TCG-based Integrity Measurement Architecture
,
2004,
USENIX Security Symposium.
[2]
Trent Jaeger,et al.
PRIMA: policy-reduced integrity measurement architecture
,
2006,
SACMAT '06.
[3]
Zou Deqing,et al.
Virtualization-Based Security Monitoring
,
2012
.
[4]
J. Aaron Pendergrass,et al.
Linux kernel integrity measurement using contextual inspection
,
2007,
STC '07.
[5]
Fu Xiang-ping.
Dynamic Integrity Measurement Model Based on Trusted Computing
,
2012
.
[6]
Yao Wang,et al.
An In-Out-VM measurement architecture against dynamic attacks in clouds
,
2012,
2012 IEEE 14th International Conference on Communication Technology.
[7]
Robert H. Deng,et al.
Remote attestation on program execution
,
2008,
STC '08.
[8]
Elaine Shi,et al.
BIND: a fine-grained attestation service for secure distributed systems
,
2005,
2005 IEEE Symposium on Security and Privacy (S&P'05).