2018
DOI: 10.3390/sym10070253
|View full text |Cite
|
Sign up to set email alerts
|

RIM4J: An Architecture for Language-Supported Runtime Measurement against Malicious Bytecode in Cloud Computing

Abstract: While cloud customers can benefit from migrating applications to the cloud, they are concerned about the security of the hosted applications. This is complicated by the customers not knowing whether their cloud applications are working as expected. Although memory-safety Java Virtual Machine (JVM) can alleviate their anxiety due to the control flow integrity, their applications are prone to a violation of bytecode integrity. The analysis of some Java exploits indicates that the violation results primarily from… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
4
0

Year Published

2018
2018
2023
2023

Publication Types

Select...
2
2

Relationship

2
2

Authors

Journals

citations
Cited by 4 publications
(4 citation statements)
references
References 35 publications
(57 reference statements)
0
4
0
Order By: Relevance
“…More measurements to be attested: Our Astrape only attests code integrity measurement to various requesters in cloud computing, which is able to determine whether the remote attested system works as expected. However, our approach can be used to leverage bytecode runtime measurement [14,29,46] to provide more dynamic protection for some high-level applications, such as Java-based cloud services. In addition, Astrape is also retrofitted to support other types of security measurements, such as the cornerstone measurements of confidentiality and availability [10,11] and virtual machine introspection-based [47,48] behavior measurements [49,50].…”
Section: Discussion and Limitationmentioning
confidence: 99%
See 1 more Smart Citation
“…More measurements to be attested: Our Astrape only attests code integrity measurement to various requesters in cloud computing, which is able to determine whether the remote attested system works as expected. However, our approach can be used to leverage bytecode runtime measurement [14,29,46] to provide more dynamic protection for some high-level applications, such as Java-based cloud services. In addition, Astrape is also retrofitted to support other types of security measurements, such as the cornerstone measurements of confidentiality and availability [10,11] and virtual machine introspection-based [47,48] behavior measurements [49,50].…”
Section: Discussion and Limitationmentioning
confidence: 99%
“…On the other hand, a secure network connection between a requester and an attester is requisite to satisfy the confidentiality requirement and not to expose the detailed information of the attested system, such as a TLS/SSL-protected connection.In a cloud environment, a set of requesters may simultaneously raise their requests to challenge the same target, such as attestations on security monitor systems [9][10][11] or microservices-based cloud systems [12]. While some previous works proposed techniques for TPM-based attestation over a secure connection [6,13,14], they focused on the single-requester scenario. If every requester is to run a standard attestation, the throughput of the attester would be extremely low due to the numerous operations in the signature and encryption.…”
mentioning
confidence: 99%
“…In [11], the authors discussed the security challenges associated with migrating applications to the cloud. They highlighted the difficulty caused by customers' lack of awareness regarding the proper functioning and security of their cloud-based applications.…”
Section: Literature Reviewmentioning
confidence: 99%
“…In a public cloud, the security issues are always critical. Researches [1][2][3][4][5][6][7] about confidentiality, integrity, availability, auditability and so on are proposed to address various security problems. However, if a cloud service provider (CSP) is suspicious, the security problems cloud become much more complicated.…”
Section: Introductionmentioning
confidence: 99%