Title:
Towards Self-Healing Systems: Re-establishing Trust in Compromised Systems

Thumbnail Image
Author(s)
Grizzard, Julian B.
Authors
Advisor(s)
Owen, Henry L., III
Advisor(s)
Editor(s)
Associated Organization(s)
Series
Supplementary to
Abstract
Computer systems are subject to a range of attacks that can compromise their intended operations. Conventional wisdom states that once a system has been compromised, the only way to recover is to format and reinstall. In this work, we present methods to automatically recover or self-heal from a compromise. We term the system an intrusion recovery system. The design consists of a layered architecture in which the production system and intrusion recovery system run in separate isolated virtual machines. The intrusion recovery system monitors the integrity of the production system and repairs state if a compromise is detected. A method is introduced to track the dynamic control flow graph of the production system guest kernel. A prototype of the system was built and tested against a suite of rootkit attacks. The system was able to recover from all attacks at a cost of about a 30% performance penalty.
Sponsor
Date Issued
2006-04-10
Extent
837686 bytes
Resource Type
Text
Resource Subtype
Dissertation
Rights Statement
Rights URI