This document presents IntTest, a framework for scalable and effective integrity attestation of services in software-as-a-service clouds. IntTest uses an integrated attestation graph analysis approach to more accurately pinpoint malicious attackers compared to previous methods. It examines both per-function consistency graphs and a global inconsistency graph to limit the scope of damage from colluding attackers. Experimental results on a production cloud system show IntTest achieves higher attacker pinpointing accuracy than existing approaches with minimal performance overhead.
Related topics: