TY - JOUR
T1 - Design of function for tracing diffusion of classified information for IPC on KVM
AU - Fujii, Shota
AU - Sato, Masaya
AU - Yamauchi, Toshihiro
AU - Taniguchi, Hideo
N1 - Publisher Copyright:
© 2016 Information Processing Society of Japan.
PY - 2016
Y1 - 2016
N2 - The leaking of information has increased in recent years. To address this problem, we previously proposed a function for tracing the diffusion of classified information in a guest OS using a virtual machine monitor (VMM). This function makes it possible to grasp the location of classified information and detect information leakage without modifying the source codes of the guest OS. The diffusion of classified information is caused by a file operation, child process creation, and inter-process communication (IPC). In a previous study, we implemented the proposed function for a file operation and child process creation excluding IPC using a kernel-based virtual machine (KVM). In this paper, we describe the design of the proposed function for IPC on a KVM without modifying the guest OS. The proposed function traces the local and remote IPCs inside the guest OS from the outside so as to trace the information diffusion. Because IPC with an outside computer might cause information leakage, tracing the IPCs enables the detection of such a leakage. We also report the evaluation results including the traceability and performance of the proposed function.
AB - The leaking of information has increased in recent years. To address this problem, we previously proposed a function for tracing the diffusion of classified information in a guest OS using a virtual machine monitor (VMM). This function makes it possible to grasp the location of classified information and detect information leakage without modifying the source codes of the guest OS. The diffusion of classified information is caused by a file operation, child process creation, and inter-process communication (IPC). In a previous study, we implemented the proposed function for a file operation and child process creation excluding IPC using a kernel-based virtual machine (KVM). In this paper, we describe the design of the proposed function for IPC on a KVM without modifying the guest OS. The proposed function traces the local and remote IPCs inside the guest OS from the outside so as to trace the information diffusion. Because IPC with an outside computer might cause information leakage, tracing the IPCs enables the detection of such a leakage. We also report the evaluation results including the traceability and performance of the proposed function.
KW - Information leakage prevention
KW - Inter-process communication
KW - Virtualization
UR - http://www.scopus.com/inward/record.url?scp=84987934441&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=84987934441&partnerID=8YFLogxK
U2 - 10.2197/ipsjjip.24.781
DO - 10.2197/ipsjjip.24.781
M3 - Article
AN - SCOPUS:84987934441
SN - 0387-5806
VL - 24
SP - 781
EP - 792
JO - Journal of Information Processing
JF - Journal of Information Processing
IS - 5
ER -