A Secure Virtual Execution Environment for Untrusted Code

A Secure Virtual Execution Environment for Untrusted Code
复制标题

用于不受信任代码的安全虚拟执行环境

DOI:
10.1007/978-3-540-76788-6_13
复制
发表时间:
2007
期刊:
Trans. High Perform. Embed. Archit. Compil.
影响因子:
--
通讯作者:
Huaimin Wang
Huaimin Wang
中科院分区:
--
文献类型:
--
作者:
Yan Wen;Huaimin Wang

文献摘要

参考文献

被引文献

相似文献

本文提出了一个安全的虚拟执行环境Pollux不可信的代码。Pollux实现了操作系统隔离和隔离的不可信应用程序提供的功能优势。它通过引入托管虚拟机作为不可信代码容器来实现操作系统隔离。Pollux的关键特征是其再现主机执行环境的能力,因此隔离应用程序的行为就像它们在主机操作系统中本机运行一样重复出现。这一特征是通过新颖的本地引导技术实现的,这意味着虚拟机不是从新安装的操作系统映像引导,而是仅从预安装的主机操作系统引导。因此,Pollux提供针对潜在恶意代码的安全性,而不会否定良性程序的功能优势。本文重点介绍了Pollux的体系结构,并概述了实现框架。
This paper proposes a Secure Virtual Execution Environment called Pollux for untrusted code. Pollux achieves both the OS isolation and the functionality benefits provided by the isolated untrusted applications. It accomplishes the OS isolation by introducing a hosted virtual machine as the untrusted code container. The key feature of Pollux is its capability of reproducing the host execution environment, thus the behavior of isolated applications recurs as if they were running natively within the host OS. This characteristic is accomplished by the novel local-booted technology, which means the virtual machine boots not from a newly installed OS image but just from the preinstalled host OS. Thus, Pollux provides security against potential malicious code without negating the functionality benefits of benign programs. This paper focuses on the architecture of Pollux and outlines the implementation framework.
计算机系统架构的进展
DOI: 10.1007/11859802_38
发表时间: 2006
期刊: --
影响因子: --
作者:
McGuiness J
通讯作者: McGuiness J