OS Support for Application Installation, Execution, and Management in an Untrustworthy World
OS Support for Application Installation, Execution, and Management in an Untrustworthy World
批准号:
0430477
负责人:
Steven Gribble
金额:
$45.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2004
资助国家:
美国
项目状态:
已结题
起止时间:
2004-09-15 至 2008-08-31
中文摘要
提案编号:0430477标题:在一个不可信的世界中为应用程序安装、执行和管理提供操作系统支持PI:Steven Gritble现代计算机用户面临许多安全威胁和可管理性障碍。今天的软件越来越复杂、有漏洞,而且容易受到攻击。除了蠕虫和病毒等熟悉的威胁外,用户还必须应对新的、更微妙的攻击,如间谍软件的传播。不幸的是,操作系统在帮助用户解决网络环境的安全和脆弱性挑战方面做得很少。例如,很难确定系统上正在运行哪些程序,或者哪些代码负责生成可见活动(如网络流量、文件系统活动或窗口活动)。本研究致力于构建一种基于轻量级虚拟机的新的应用程序和操作系统架构,每个应用程序都安装并隔离在自己的虚拟机中。安装和删除应用程序变得很简单,因为VM提供了一个干净的容器,可以在其中嵌入所有应用程序依赖项和资源。跟踪应用程序并将活动与其源相关联成为可能,因为可以通过狭窄的VM界面轻松地观察和跟踪活动。这种架构提供了更强大的安全属性,因为恶意应用程序与良性程序和数据隔离,应用程序中的漏洞不再将其他应用程序置于风险之中。这项工作的影响将是为用户提供他们可以依赖的可靠基础设施,并在攻击成功的情况下减轻对用户的损害。
英文摘要
Proposal Number: 0430477TItle: OS Support for Application Installation, Execution, and Management inan Untrustworthy WorldPI: Steven Gribble Modern computer users face many security threats and manageability obstacles. Today's software is increasingly complex, buggy, and prone to vulnerability. In addition to familiar threats such as worms and viruses, users must contend with new, more subtle attacks, such as the spread of spyware. Unfortunately, operating systems do little to help users address the security and vulnerability challenges of the networked environment. For example, it is difficult to determine what programs are running on a system, or what code is responsible for generating visible activity (such as network traffic, file system activity, or windowing activity). This research focuses on the construction of a new application and operating system architecture based on lightweight virtual machines, with each application being both installed and isolated in its own VM. Installing and removing applications becomes simple, as a VM provides a clean container in which all of the application dependencies and resources can be embedded. Tracking an application and associating activity with its source becomes possible, since activity is easily observable through and traceable to the narrow VM interface. This architecture provides stronger security properties, since malicious applications are isolated from benign programs and data, and a vulnerability within an application no longer puts other applications at risk. The impact of this work will be to provide users with trustworthy infrastructure that they can depend on, and to mitigate damage to users in the case of successful attacks.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Student Travel Support for the Ninth Symposium on Networked Systems Design and Implementation (NSDI 2012)
-
批准号:1232584
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:2012
-
负责人:Steven Gribble
-
依托单位:
Student Travel Support for the 10th USENIX Symposium on Operating Systems Design and Implementation (OSDI 2012)
-
批准号:1249332
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:2012
-
负责人:Steven Gribble
-
依托单位:
CSR: Small: Bringing Predictable Low Latency and Strong Consistency to Data Center Services
-
批准号:1217597
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2012
-
负责人:Steven Gribble
-
依托单位:
CSR: Small: Driverless Operating Systems
-
批准号:1016477
-
项目类别:Standard Grant
-
资助金额:$49.99万
-
财政年份:2010
-
负责人:Steven Gribble
-
依托单位:
CT-T: The Detection and Prevention of Spyware
-
批准号:0627367
-
项目类别:Continuing Grant
-
资助金额:$95.0万
-
财政年份:2006
-
负责人:Steven Gribble
-
依托单位:
CAREER: Enabling New Networking Applications and Distributed Systems with Mobile, Lightweight Protection Domains
-
批准号:0132817
-
项目类别:Standard Grant
-
资助金额:$49.93万
-
财政年份:2002
-
负责人:Steven Gribble
-
依托单位:
国内基金
海外基金
两性离子载体(zwitterionic support)作为可溶性支载体在液相有机合成中的应用
-
批准号:21002080
-
项目类别:青年科学基金项目
-
资助金额:19.0万元
-
批准年份:2010
-
负责人:霍聪德
-
依托单位:
基于Support Vector Machines(SVMs)算法的智能型期权定价模型的研究
-
批准号:70501008
-
项目类别:青年科学基金项目
-
资助金额:17.0万元
-
批准年份:2005
-
负责人:曹丽娟
-
依托单位: