首页> 外文会议>Computer Security Foundations Workshop >Protection against covert storage and timing channels
【24h】

Protection against covert storage and timing channels

机译:防止隐蔽存储和定时频道

获取原文

摘要

Existing technology is quite successful at preventing direct unauthorized communication in multilevel secure computer systems, but is almost completely ineffective at protecting such systems against covert storage and timing channels. In a covert channel, one process transmits secret information by modulating its rate of use of a shared resource, while another program detects that modulation by monitoring the responsiveness of the resource. The proposed protection technique involves screening all programs in a system by a data dependency analysis procedure that determines whether the results of those programs depend on the relative timing of operations within the system. Programs containing such timing dependencies are denied access to the system until certified by other means. The approach is reasonably inexpensive and completely rigorous and, when strictly applied, precludes all communication over covert storage and timing channels.
机译:现有技术在防止多级安全计算机系统中直接未经授权的通信,但在保护这种系统免受隐蔽存储和定时通道的保护时几乎完全无效。在封面信道中,一个过程通过调制其使用速率来发送秘密信息,而另一个程序通过监视资源的响应性来检测该调制。所提出的保护技术涉及通过数据依赖性分析过程筛选系统中的所有程序,该程序确定这些程序的结果是否依赖于系统内的操作的相对时序。包含此类时序依赖项的程序被拒绝访问系统,直到其他方式认证。该方法合理廉价且完全严格,当严格应用时,妨碍了封面存储和定时频道上的所有通信。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号