On the formalization, design, and implementation of component-oriented access control in lightweight virtualized server environments

On the formalization, design, and implementation of component-oriented access control in lightweight virtualized server environments
复制标题

DOI:
10.1016/j.cose.2017.06.004
复制
发表时间:
2017-11
期刊:
Comput. Secur.
影响因子:
--
通讯作者:
K. Belyaev;I. Ray
K. Belyaev;I. Ray
中科院分区:
其他
文献类型:
--
作者:
K. Belyaev;I. Ray

文献摘要

相似文献

在诸如Linux之类的现代操作系统中,现在可以在单个服务器实例上处理大量并发应用服务。这些服务的各个应用程序组件可能在不同的隔离运行时环境中运行,例如chroot jail或应用程序容器,并且可能需要访问系统资源以及相互协作和协调的能力。我们正式的访问控制要求,这些组件,我们的模型允许访问操作系统资源的需要知道的基础上,还控制在一个单一的Linux操作系统服务器实例下的不相交的容器化环境中运行的服务组件之间的协作和协调。这种访问控制是通过Linux策略机(LPM)来管理和实施的,该LPM充当集中式引用监视器并提供用于访问系统资源和请求应用数据和控制对象的统一接口。我们提出了LPM的设计,并提供了一个实现,以证明我们的方法的可行性。
In modern day operating systems, such as Linux, it is now possible to handle a large number of concurrent application services on a single server instance. Individual application components of such services may run in different isolated runtime environments, such as chrooted jails or application containers, and may need access to system resources and the ability to collaborate and coordinate with each other. We formalize the access control requirements of such components; our model allows access to OS resources on a need-to-know basis and also controls collaboration and coordination among service components running in disjoint containerized environments under a single Linux OS server instance. Such access control is managed and enforced through a Linux Policy Machine (LPM) that acts as the centralized reference monitor and provides a uniform interface for accessing system resources and requesting application data and control objects. We present the design of the LPM and provide an implementation to demonstrate the feasibility of our approach.