Labels and event processes in the asbestos operating system
Labels and event processes in the asbestos operating system
复制标题
DOI:
10.1145/1095810.1095813
复制
发表时间:
2007-12
影响因子:
1.5
通讯作者:
P. Efstathopoulos;Maxwell N. Krohn;Steve Vandebogart;C. Frey;David Ziegler;E. Kohler;David Mazières;F. Kaashoek;R. Morris
中科院分区:
文献类型:
--
作者:
P. Efstathopoulos;Maxwell N. Krohn;Steve Vandebogart;C. Frey;David Ziegler;E. Kohler;David Mazières;F. Kaashoek;R. Morris
Asbestos, a new prototype operating system, provides novel labeling and isolation mechanisms that help contain the effects of exploitable software flaws. Applications can express a wide range of policies with Asbestos's kernel-enforced label mechanism, including controls on inter-process communication and system-wide information flow. A new event process abstraction provides lightweight, isolated contexts within a single process, allowing the same process to act on behalf of multiple users while preventing it from leaking any single user's data to any other user. A Web server that uses Asbestos labels to isolate user data requires about 1.5 memory pages per user, demonstrating that additional security can come at an acceptable cost.