{"updated":"2025-01-21T23:37:21.294994+00:00","metadata":{"_oai":{"id":"oai:ipsj.ixsq.nii.ac.jp:00070100","sets":["1164:1867:5984:6142"]},"path":["6142"],"owner":"10","recid":"70100","title":["仮想マシンを用いた既存IDSのオフロード"],"pubdate":{"attribute_name":"公開日","attribute_value":"2010-07-27"},"_buckets":{"deposit":"6ab9752a-c6c7-4545-aad6-5f27ea15804e"},"_deposit":{"id":"70100","pid":{"type":"depid","value":"70100","revision_id":0},"owners":[10],"status":"published","created_by":10},"item_title":"仮想マシンを用いた既存IDSのオフロード","author_link":["0","0"],"item_titles":{"attribute_name":"タイトル","attribute_value_mlt":[{"subitem_title":"仮想マシンを用いた既存IDSのオフロード"},{"subitem_title":"Offloading Existing IDSes Using Virtual Machines","subitem_title_language":"en"}]},"item_keyword":{"attribute_name":"キーワード","attribute_value_mlt":[{"subitem_subject":"仮想化(2)","subitem_subject_scheme":"Other"}]},"item_type_id":"4","publish_date":"2010-07-27","item_4_text_3":{"attribute_name":"著者所属","attribute_value_mlt":[{"subitem_text_value":"九州工業大学"},{"subitem_text_value":"九州工業大学/独立行政法人科学技術振興機構, CREST"}]},"item_4_text_4":{"attribute_name":"著者所属(英)","attribute_value_mlt":[{"subitem_text_value":"Kyushu Institute of Technology","subitem_text_language":"en"},{"subitem_text_value":"Kyushu Institute of Technology / Japan Science and Technology Agency, CREST","subitem_text_language":"en"}]},"item_language":{"attribute_name":"言語","attribute_value_mlt":[{"subitem_language":"jpn"}]},"item_publisher":{"attribute_name":"出版者","attribute_value_mlt":[{"subitem_publisher":"情報処理学会","subitem_publisher_language":"ja"}]},"publish_status":"0","weko_shared_id":-1,"item_file_price":{"attribute_name":"Billing file","attribute_type":"file","attribute_value_mlt":[{"url":{"url":"https://ipsj.ixsq.nii.ac.jp/record/70100/files/IPSJ-OS10115021.pdf"},"date":[{"dateType":"Available","dateValue":"2012-07-27"}],"format":"application/pdf","billing":["billing_file"],"filename":"IPSJ-OS10115021.pdf","filesize":[{"value":"500.4 kB"}],"mimetype":"application/pdf","priceinfo":[{"tax":["include_tax"],"price":"660","billingrole":"5"},{"tax":["include_tax"],"price":"330","billingrole":"6"},{"tax":["include_tax"],"price":"0","billingrole":"11"},{"tax":["include_tax"],"price":"0","billingrole":"44"}],"accessrole":"open_date","version_id":"d80acb77-9ea2-4bce-a582-b60f6e0acb5c","displaytype":"detail","licensetype":"license_note","license_note":"Copyright (c) 2010 by the Information Processing Society of Japan"}]},"item_4_creator_5":{"attribute_name":"著者名","attribute_type":"creator","attribute_value_mlt":[{"creatorNames":[{"creatorName":"飯田, 貴大"},{"creatorName":"光来, 健一"}],"nameIdentifiers":[{}]}]},"item_4_creator_6":{"attribute_name":"著者名(英)","attribute_type":"creator","attribute_value_mlt":[{"creatorNames":[{"creatorName":"Takahiro, Iida","creatorNameLang":"en"},{"creatorName":"Kennichi, Kourai","creatorNameLang":"en"}],"nameIdentifiers":[{}]}]},"item_4_source_id_9":{"attribute_name":"書誌レコードID","attribute_value_mlt":[{"subitem_source_identifier":"AN10444176","subitem_source_identifier_type":"NCID"}]},"item_4_textarea_12":{"attribute_name":"Notice","attribute_value_mlt":[{"subitem_textarea_value":"SIG Technical Reports are nonrefereed and hence may later appear in any journals, conferences, symposia, etc."}]},"item_resource_type":{"attribute_name":"資源タイプ","attribute_value_mlt":[{"resourceuri":"http://purl.org/coar/resource_type/c_18gh","resourcetype":"technical report"}]},"item_4_description_7":{"attribute_name":"論文抄録","attribute_value_mlt":[{"subitem_description":"侵入検知システム (IDS) を安全に実行できるようにするために、仮想マシンを用いて IDS をオフロードするという手法が提案されている。この手法は監視対象のシステムを仮想マシン上で動作させ、IDS だけ別の仮想マシン上で動作させる手法である。しかし、IDS をオフロードして動作させられるようにするためには多大な労力を必要とすることが多い。本稿ではオフロードした IDS に修正を加えることなく動作させられるようにする Transcall を提案する。Transcall はオフロード元の仮想マシンを監視するための実行環境である VM シャドウを提供する。Transcall は VM シャドウ内のプロセスに対して、システムコールのエミュレーションを行い、シャドウファイルシステムを提供する。VM シャドウ内で IDS を動作させることで、オフロード元の仮想マシンを監視させることができる。","subitem_description_type":"Other"}]},"item_4_description_8":{"attribute_name":"論文抄録(英)","attribute_value_mlt":[{"subitem_description":"To execute intrusion detection systems (IDSes) securely, offloading IDSes with virtual machines (VMs) has been proposed. This technique runs a monitored system on a VM and executes only IDSes on another VM. However, the proper execution of offloaded IDSes often requires great efforts. This paper proposes Transcall, which enables offloaded IDSes to be executed without any modification. Transcall provides an execution environment for monitoring a VM, called a VM shadow. Transcall emulates system calls and provides a shadow filesystem for processes in a VM shadow. Executing IDSes in a VM shadow enables monitoring the corresponding VM.","subitem_description_type":"Other"}]},"item_4_biblio_info_10":{"attribute_name":"書誌情報","attribute_value_mlt":[{"bibliographicPageEnd":"8","bibliographic_titles":[{"bibliographic_title":"研究報告システムソフトウェアと オペレーティング・システム(OS)"}],"bibliographicPageStart":"1","bibliographicIssueDates":{"bibliographicIssueDate":"2010-07-27","bibliographicIssueDateType":"Issued"},"bibliographicIssueNumber":"21","bibliographicVolumeNumber":"2010-OS-115"}]},"relation_version_is_last":true,"weko_creator_id":"10"},"created":"2025-01-18T23:29:24.383567+00:00","id":70100,"links":{}}