首页> 外文会议>Computer Security Applications Conference, 2009. ACSAC '09 >Justifying Integrity Using a Virtual Machine Verifier
【24h】

Justifying Integrity Using a Virtual Machine Verifier

机译:使用虚拟机验证程序证明完整性

获取原文

摘要

Emerging distributed computing architectures, such as grid and cloud computing, depend on the high integrity execution of each system in the computation. While integrity measurement enables systems to generate proofs of their integrity to remote parties, we find that current integrity measurement approaches are insufficient to prove runtime integrity for systems in these architectures. Integrity measurement approaches that are flexible enough have an incomplete view of runtime integrity, possibly leading to false integrity claims, and approaches that provide comprehensive integrity do so only for computing environments that are too restrictive. In this paper, we propose an architecture for building comprehensive runtime integrity proofs for general purpose systems in distributed computing architectures. In this architecture, we strive for classical integrity, using an approximation of the Clark-Wilson integrity model as our target. Key to building such integrity proofs is a carefully crafted host system whose long-term integrity can be justified easily using current techniques and a new component, called a VM verifier, which comprehensively enforces our integrity target on VMs. We have built a prototype based on the Xen virtual machine system for SELinux VMs, and find that distributed compilation can be implemented, providing accurate proofs of our integrity target with less than 4% overhead.
机译:诸如网格和云计算之类的新兴分布式计算体系结构取决于计算中每个系统的高完整性执行。尽管完整性度量使系统能够生成对远程方的完整性证明,但我们发现当前的完整性度量方法不足以证明这些体系结构中系统的运行时完整性。足够灵活的完整性度量方法对运行时完整性没有完整的了解,这可能导致错误的完整性声明,而提供全面完整性的方法仅适用于过于严格的计算环境。在本文中,我们提出了一种用于为分布式计算体系结构中的通用系统构建全面的运行时完整性证明的体系结构。在这种体系结构中,我们以Clark-Wilson完整性模型的近似值为目标来追求经典完整性。构建此类完整性证明的关键是精心设计的主机系统,该主机系统可以使用当前技术轻松地证明其长期完整性,以及一个名为VM验证程序的新组件,该组件可以在VM上全面实施我们的完整性目标。我们已经针对SELinux VM建立了基于Xen虚拟机系统的原型,发现可以实现分布式编译,从而以不到4%的开销提供了我们的完整性目标的准确证明。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号