Building a MAC-based security architecture for the Xen open-source hypervisor

Building a MAC-based security architecture for the Xen open-source hypervisor
复制标题

DOI:
10.1109/csac.2005.13
复制
发表时间:
2005-12
期刊:
21st Annual Computer Security Applications Conference (ACSAC'05)
影响因子:
--
通讯作者:
R. Sailer;T. Jaeger;Enriquillo Valdez;R. Cáceres;R. Perez;Stefan Berger;J. Griffin;L. V. Doorn
R. Sailer;T. Jaeger;Enriquillo Valdez;R. Cáceres;R. Perez;Stefan Berger;J. Griffin;L. V. Doorn
中科院分区:
其他
文献类型:
--
作者:
R. Sailer;T. Jaeger;Enriquillo Valdez;R. Cáceres;R. Perez;Stefan Berger;J. Griffin;L. V. Doorn

文献摘要

被引文献

相似文献

我们介绍 sHype 虚拟机管理程序安全架构,并详细检查其强制访问控制设施。虽然旨在高保证的现有虚拟机管理程序安全方法已被证明对于将安全性置于性能和代码重用之上的高安全性环境非常有用,但我们的方法旨在商业安全,其中接近零的性能开销、非侵入式实施和可用性至关重要。 sHype 在虚拟机的粒度上强制执行强隔离,从而为更高的软件层可以实施更细粒度的控制提供了坚实的基础。我们提供 sHype 设计背后的基本原理,并描述和评估我们对 Xen 开源虚拟机管理程序的实施
We present the sHype hypervisor security architecture and examine in detail its mandatory access control facilities. While existing hypervisor security approaches aiming at high assurance have been proven useful for high-security environments that prioritize security over performance and code reuse, our approach aims at commercial security where near-zero performance overhead, non-intrusive implementation, and usability are of paramount importance. sHype enforces strong isolation at the granularity of a virtual machine, thus providing a robust foundation on which higher software layers can enact finer-grained controls. We provide the rationale behind the sHype design and describe and evaluate our implementation for the Xen open-source hypervisor