USENIX Security2026Top-tier venue
HyperAudit: Towards User Transparent and Highly Efficient System Auditing for Cloud Platforms
Renpeng Zhang, Kai Shen, Peng Jiang, Ding Li, Shujiang Wu, Lei Wang
Abstract
System auditing is a critical security primitive for cloud platforms, but existing auditing frameworks place the log collection module inside the compromise-prone guest kernel. This design exposes a large attack surface and enables race condition attacks, where an attacker that compromises the kernel can tamper with uncommitted logs and erase pre-compromise traces. Prior secure collectors mitigate this by frequent synchronous or timed submissions, which incur non-trivial runtime overhead. We present HyperAudit, a hypervisor-assisted auditing architecture that isolates the log collection module from the guest kernel while keeping collection efficient and deployable. HyperAudit injects a kernel-independent collector into a hidden memory region, protects its code with execute-only permissions, and shields the log buffer with guard-page trapping, minimizing the exposed attack surface. Logs are asynchronously pulled by a consumer in a dedicated Secure VM, avoiding periodic synchronous commits. Under the common auditing assumption that logs generated after kernel compromise are untrustworthy, HyperAudit guarantees the integrity of all pre-compromise logs against race condition and flooding attacks. We implement HyperAudit on both x86 and Arm without extra hardware, and show that it reduces log-intensive application overhead by 49% and 66% compared to eAudit and HitchHiker, even outperforming host-only collectors.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0d81836a-42d9-4edd-89ac-eb577df33649Builds on15
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar et al.S&P 2019 · 550 citations
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp et al.CCS 2016 · 278 citations
- HARDLOG: Practical Tamper-Proof System Auditing Using a Novel Audit DeviceAdil Ahmad, Sangho Lee, Marcus PeinadoS&P 2022 · 46 citations
- Logging to the Danger Zone: Race Condition Attacks and Defenses on System Audit FrameworksRiccardo Paccagnella, Kevin Liao, Dave Tian, Adam BatesCCS 2020 · 43 citations
- eAudit: A Fast, Scalable and Deployable Audit Data Collection SystemR. Sekar, Hanke Kimm, Rohit AichS&P 2024 · 31 citations
Related papers
- The HitchHiker's Guide to High-Assurance System Observability Protection with Efficient Permission SwitchesChuqi Zhang, Jun Zeng, Yiming Zhang, Adil Ahmad et al.CCS 2024 · 4 citations
- Fine-Grained Kernel Auditing Using Augmented Syscall Reference Behavior Analysis and Virtualized Selective TracingChuqi Zhang, Spencer Faith, Feras Al-Qassas, Theodorus Februanto et al.S&P 2026
- Rethinking System Audit Architectures for High Event Coverage and Synchronous Log AvailabilityVarun Gandhi, Sarbartha Banerjee, Aniket Agrawal, Adil Ahmad et al.USENIX Security 2023
- DPUaudit: DPU-assisted Pull-based Architecture for Near-Zero Cost System AuditingPeng Jiang, Hanlin Jiang, Ruizhe Huang, Hanwen Lei et al.HPCA 2025 · 3 citations
- HYPERPILL: Fuzzing for Hypervisor-bugs by leveraging the Hardware Virtualization InterfaceAlexander Bulekov, Qiang Liu, Manuel Egele, Mathias PayerUSENIX Security 2024 · 15 citations
