首页> 外文会议>IEEE International Symposium on Policies for Distributed Systems and Networks >A Virtualization Assurance Language for Isolation and Deployment
【24h】

A Virtualization Assurance Language for Isolation and Deployment

机译:用于隔离和部署的虚拟化保证语言

获取原文
获取外文期刊封面目录资料

摘要

Cloud computing and virtualized infrastructures are often accompanied by complex configurations and topologies. Dynamic scaling, rapid virtual machine deployment, and open multi-tenant architectures create an environment, in which local misconfiguration can create subtle security risks for the entire infrastructure. This situation calls for automated deployment as well as analysis mechanisms, which in turn require a cloud assurance policy language to express security goals for such environments. Where possible, configuration changes should be statically checked against the policy prior to implementation on the infrastructure. We study security requirements of virtualized infrastructures and propose a practical tool-independent policy language for security assurance. Our policy proposal has a formal foundation, and still allows for efficient specification of a variety of security goals, such as isolation. In addition, we offer language provisions to compare a desired state against an actual state, discovered in the configuration, and thus allow for a differential analysis. The language is well-suited for automated deduction, be it by model checking or theorem proving.
机译:云计算和虚拟化基础架构通常伴随着复杂的配置和拓扑。动态缩放,快速虚拟机部署和打开的多租户架构创建一个环境,其中本地错误配置可以为整个基础架构创造微妙的安全风险。这种情况要求自动部署以及分析机制,这反过来需要云保证政策语言来表达此类环境的安全目标。在可能的情况下,应在基础架构执行之前静态检查配置更改。我们研究了虚拟化基础设施的安全要求,并提出了一种实用的独立政策语言,以确保安全保证。我们的政策提案具有正式的基础,仍然允许有效规范各种安全目标,例如隔离。此外,我们提供语言规定,以将所需状态与在配置中发现的实际状态进行比较,从而允许差异分析。该语言非常适合自动扣除,通过模型检查或定理证明。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号