PRIMA: policy-reduced integrity measurement architecture

PRIMA: policy-reduced integrity measurement architecture
复制标题

DOI:
10.1145/1133058.1133063
复制
发表时间:
2006-06
期刊:
--
影响因子:
--
通讯作者:
T. Jaeger;R. Sailer;U. Shankar
T. Jaeger;R. Sailer;U. Shankar
中科院分区:
其他
文献类型:
--
作者:
T. Jaeger;R. Sailer;U. Shankar

文献摘要

被引文献

相似文献

本文提出了一种基于信息流完整性的完整性度量方法,称为策略简化完整性度量体系结构(PRIMA).人们已经提出了各种方法,但大多数方法都只是简单地测量加载的代码和静态数据来估计运行时系统的完整性。我们发现这些方法存在两个问题:(1)单独的代码的加载时间测量不能准确地反映运行时行为,例如使用不可信的网络数据,以及(2)它们是低效的,要求所有被测量的实体都是已知的和完全可信的,即使它们对目标应用程序没有影响。经典的完整性模型是基于信息流的,因此,我们设计的PRIMA方法,使信息流完整性的测量,并证明它实现了这些目标。我们证明了如何远程方可以验证有用的信息流的完整性属性使用PRIMA。基于开源的Linux完整性度量体系结构(IMA),利用SE Linux策略提供信息流,构建了PRIMA原型。
We propose an integrity measurement approach based on information flow integrity,which we call the Policy-Reduced Integrity Measurement Architecture (PRIMA).The recent availability of secure hardware has made it practical for a system to measure its own integrity, such that it can generate an integrity proof for remote parties. Various approaches have been proposed,but most simply measure the loaded code and static data to approximate runtime system integrity.We find that these approaches suffer from two problems: (1)the load-time measurements of code alone do not accurately reflect runtime behaviors,such as the use of untrusted network data,and (2) they are ineficient,requiring all measured entities to be known and fully trusted even if they have no impact on the target application.Classical integrity models are based on information flow,so we design the PRIMA approach to enable measurement of information flow integrity and prove that it achieves these goals. We prove how a remote party can verify useful information flow integrity properties using PRIMA. A PRIMA prototype has been built based on the open-source Linux Integrity Measurement Architecture (IMA)using SELinux policies to provide the information flow.