A Secure Virtual Execution Environment for Untrusted Code
A Secure Virtual Execution Environment for Untrusted Code
复制标题
用于不受信任代码的安全虚拟执行环境
DOI:
10.1007/978-3-540-76788-6_13
复制
发表时间:
2007
期刊:
影响因子:
--
通讯作者:
Huaimin Wang
中科院分区:
文献类型:
--
作者:
Yan Wen;Huaimin Wang
This paper proposes a Secure Virtual Execution Environment called Pollux for untrusted code. Pollux achieves both the OS isolation and the functionality benefits provided by the isolated untrusted applications. It accomplishes the OS isolation by introducing a hosted virtual machine as the untrusted code container. The key feature of Pollux is its capability of reproducing the host execution environment, thus the behavior of isolated applications recurs as if they were running natively within the host OS. This characteristic is accomplished by the novel local-booted technology, which means the virtual machine boots not from a newly installed OS image but just from the preinstalled host OS. Thus, Pollux provides security against potential malicious code without negating the functionality benefits of benign programs. This paper focuses on the architecture of Pollux and outlines the implementation framework.
DOI:
10.1007/11859802_38
发表时间:
2006
期刊:
--
影响因子:
--
作者:
McGuiness J
通讯作者:
McGuiness J