Affiliation:
1. University of Utah, Salt Lake City, UT, USA
Abstract
Virtual machine introspection (VMI) allows users to debug software that executes within a virtual machine. To support rich, whole-system analyses, a VMI tool must inspect and control systems at multiple levels of the software stack. Traditional debuggers enable inspection and control, but they limit users to treating a whole system as just one kind of target: e.g., just a kernel, or just a process, but not both.
We created Stackdb, a debugging library with VMI support that allows one to monitor and control a whole system through multiple, coordinated targets. A target corresponds to a particular level of the system's software stack; multiple targets allow a user to observe a VM guest at several levels of abstraction simultaneously. For example, with Stackdb, one can observe a PHP script running in a Linux process in a Xen VM via three coordinated targets at the language, process, and kernel levels. Within Stackdb, higher-level targets are components that utilize lower-level targets; a key contribution of Stackdb is its API that supports multi-level and flexible "stacks" of targets. This paper describes the challenges we faced in creating Stackdb, presents the solutions we devised, and evaluates Stackdb through its application to a security-focused, whole-system case study.
Publisher
Association for Computing Machinery (ACM)
Subject
Computer Graphics and Computer-Aided Design,Software
Cited by
6 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
1. Tenant-Oriented Monitoring for Customized Security Services in the Cloud;Symmetry;2019-02-18
2. HYDRA;Proceedings of the 13th International Conference on Availability, Reliability and Security;2018-08-27
3. Hyperagents;Proceedings of the Eighth ACM Conference on Data and Application Security and Privacy;2018-03-13
4. ATOM: Efficient Tracking, Monitoring, and Orchestration of Cloud Resources;IEEE Transactions on Parallel and Distributed Systems;2017-08-01
5. Software Tools for Low-Level Software and Operating Systems Classes;Proceedings of the 19th Workshop on Computer Architecture Education;2017-06-24