【24h】

Page reclamation technique for VMM based application sandbox

机译:基于VMM的应用程序沙箱的页面回收技术

获取原文
获取原文并翻译 | 示例

摘要

Sandbox, process container and process isolation all provide the design to control and monitor execution of untrusted applications. Most of these solutions use virtualization to provide VM-equivalent isolation for sandboxed process. Sandboxing incurs sufficient overheads in providing secure execution of untrusted binary. Memory is one of such resources which can be bottleneck for scalability of sandbox to control execution of most of apps on single system. In this research, we present a novel page reclamation technique to reclaim pages from sandboxed applications. Page reclamation evicts pages of process which are least recently used in active working set. Proposed technique use Page modification logging (PML) hardware virtualization extension to get working set of isolated process. We implemented proposed technique as extension to one of sandboxes that use hardware virtualization extensions. In evaluation, we successfully reclaim 5% to 11% memory with negligible CPU overhead.
机译:沙盒,进程容器和进程隔离都提供了控制和监视不受信任的应用程序执行的设计。这些解决方案中的大多数都使用虚拟化为沙盒过程提供与VM等效的隔离。沙盒在提供不受信任的二进制文件的安全执行时会产生足够的开销。内存是此类资源之一,可能成为沙箱可伸缩性的瓶颈,以控制单个系统上大多数应用程序的执行。在这项研究中,我们提出了一种新颖的页面回收技术来从沙盒应用程序中回收页面。页面回收驱逐了活动工作集中最近最少使用的过程页面。拟议的技术使用页面修改日志记录(PML)硬件虚拟化扩展来获取隔离过程的工作集。我们实施了提议的技术,作为对使用硬件虚拟化扩展的沙箱之一的扩展。在评估中,我们成功回收了5%至11%的内存,而CPU开销却可以忽略不计。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号