首页> 外文会议>Proceedings of the 9th international conference for young computer scientists (ICYCS 2008) >A Prioritized Chinese Wall Model for Managing the Covert Information Flows in Virtual Machine Systems
【24h】

A Prioritized Chinese Wall Model for Managing the Covert Information Flows in Virtual Machine Systems

机译:在虚拟机系统中管理隐秘信息流的优先中国墙模​​型

获取原文

摘要

In virtual machine (VM) systems, mandatory access control (MAC) enforcement is possible now. This technique is both stronger and more flexible than traditional VM isolation, even if network communication is controlled. Unfortunately all of the VM systems with the MAC enforcement does not consider that the MAC controls may be distorted by covert channels, which constitute an important risk in VM systems. Traditional MAC models have difficulties being enforced to reduce the risk of covert flows in VM systems due to the many constraints and the lack of flexibility. In this paper, we identify access control requirements for managing covert channels in VM systems through a critical analysis of the ways by which classical models constrain the covert information flows and we propose a model called the Prioritized Chinese Wall model (PCW) to reduce the risk of covert flows in VM systems while preserving the flexibility. Furthermore, we enforce the policy in sHype/Xen VM system.
机译:在虚拟机(VM)系统中,现在可以强制执行强制访问控制(MAC)。即使控制网络通信,该技术也比传统的VM隔离更强大,更灵活。不幸的是,所有实施了MAC的VM系统都没有考虑到MAC控件可能会被隐蔽通道所扭曲,这在VM系统中构成了重要的风险。由于存在许多约束和缺乏灵活性,传统的MAC模型很难实施以降低VM系统中隐蔽流的风险。在本文中,我们通过对经典模型约束隐性信息流的方式进行批判性分析,确定了在VM系统中管理隐秘通道的访问控制要求,并提出了一种称为优先中国墙模​​型(PCW)的模型来降低风险VM系统中的隐蔽流,同时保留了灵活性。此外,我们在sHype / Xen VM系统中执行该策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号