Lune

USENIX Security2026顶会

HyperAudit: Towards User Transparent and Highly Efficient System Auditing for Cloud Platforms

Renpeng Zhang, Kai Shen, Peng Jiang, Ding Li, Shujiang Wu, Lei Wang

出版方
2026年份

摘要

System auditing is a critical security primitive for cloud platforms, but existing auditing frameworks place the log collection module inside the compromise-prone guest kernel. This design exposes a large attack surface and enables race condition attacks, where an attacker that compromises the kernel can tamper with uncommitted logs and erase pre-compromise traces. Prior secure collectors mitigate this by frequent synchronous or timed submissions, which incur non-trivial runtime overhead. We present HyperAudit, a hypervisor-assisted auditing architecture that isolates the log collection module from the guest kernel while keeping collection efficient and deployable. HyperAudit injects a kernel-independent collector into a hidden memory region, protects its code with execute-only permissions, and shields the log buffer with guard-page trapping, minimizing the exposed attack surface. Logs are asynchronously pulled by a consumer in a dedicated Secure VM, avoiding periodic synchronous commits. Under the common auditing assumption that logs generated after kernel compromise are untrustworthy, HyperAudit guarantees the integrity of all pre-compromise logs against race condition and flooding attacks. We implement HyperAudit on both x86 and Arm without extra hardware, and show that it reduces log-intensive application overhead by 49% and 66% compared to eAudit and HitchHiker, even outperforming host-only collectors.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper15

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖