HyperAudit: Towards User Transparent and Highly Efficient System Auditing for Cloud Platforms
Renpeng Zhang, Kai Shen, Peng Jiang, Ding Li, Shujiang Wu, Lei Wang
摘要
System auditing is a critical security primitive for cloud platforms, but existing auditing frameworks place the log collection module inside the compromise-prone guest kernel. This design exposes a large attack surface and enables race condition attacks, where an attacker that compromises the kernel can tamper with uncommitted logs and erase pre-compromise traces. Prior secure collectors mitigate this by frequent synchronous or timed submissions, which incur non-trivial runtime overhead. We present HyperAudit, a hypervisor-assisted auditing architecture that isolates the log collection module from the guest kernel while keeping collection efficient and deployable. HyperAudit injects a kernel-independent collector into a hidden memory region, protects its code with execute-only permissions, and shields the log buffer with guard-page trapping, minimizing the exposed attack surface. Logs are asynchronously pulled by a consumer in a dedicated Secure VM, avoiding periodic synchronous commits. Under the common auditing assumption that logs generated after kernel compromise are untrustworthy, HyperAudit guarantees the integrity of all pre-compromise logs against race condition and flooding attacks. We implement HyperAudit on both x86 and Arm without extra hardware, and show that it reduces log-intensive application overhead by 49% and 66% compared to eAudit and HitchHiker, even outperforming host-only collectors.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper15
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar 等S&P 2019 · 被引用 550 次
- Prefetch Side-Channel Attacks: Bypassing SMAP and Kernel ASLRDaniel Gruss, Clémentine Maurice, Anders Fogh, Moritz Lipp 等CCS 2016 · 被引用 278 次
- HARDLOG: Practical Tamper-Proof System Auditing Using a Novel Audit DeviceAdil Ahmad, Sangho Lee, Marcus PeinadoS&P 2022 · 被引用 46 次
- Logging to the Danger Zone: Race Condition Attacks and Defenses on System Audit FrameworksRiccardo Paccagnella, Kevin Liao, Dave Tian, Adam BatesCCS 2020 · 被引用 43 次
- eAudit: A Fast, Scalable and Deployable Audit Data Collection SystemR. Sekar, Hanke Kimm, Rohit AichS&P 2024 · 被引用 31 次
相关 Paper
- The HitchHiker's Guide to High-Assurance System Observability Protection with Efficient Permission SwitchesChuqi Zhang, Jun Zeng, Yiming Zhang, Adil Ahmad 等CCS 2024 · 被引用 4 次
- Fine-Grained Kernel Auditing Using Augmented Syscall Reference Behavior Analysis and Virtualized Selective TracingChuqi Zhang, Spencer Faith, Feras Al-Qassas, Theodorus Februanto 等S&P 2026
- Rethinking System Audit Architectures for High Event Coverage and Synchronous Log AvailabilityVarun Gandhi, Sarbartha Banerjee, Aniket Agrawal, Adil Ahmad 等USENIX Security 2023
- DPUaudit: DPU-assisted Pull-based Architecture for Near-Zero Cost System AuditingPeng Jiang, Hanlin Jiang, Ruizhe Huang, Hanwen Lei 等HPCA 2025 · 被引用 3 次
- HYPERPILL: Fuzzing for Hypervisor-bugs by leveraging the Hardware Virtualization InterfaceAlexander Bulekov, Qiang Liu, Manuel Egele, Mathias PayerUSENIX Security 2024 · 被引用 15 次
