首页> 外文学位 >Secure, efficient and manageable virtual machine systems.
【24h】

Secure, efficient and manageable virtual machine systems.

机译:安全,高效和可管理的虚拟机系统。

获取原文
获取原文并翻译 | 示例

摘要

This dissertation is about structuring, building and testing virtual machines. Virtual machine systems are compelling because they simultaneously promise extensibility, performance and safety. They can guarantee system integrity in the presence of untrusted applications, offer a uniform interface, and permit a resource-efficient implementation. While these features make modern virtual machines compelling, current state of the art virtual machine implementations suffer from fundamental problems related to resource consumption, manageability and security. Existing virtual machines perform all of the services that they rely on locally, and consequently require excessive resources on each client. In addition, virtual machines embody a significant amount of state on each client, and consequently make it difficult to administer large networks of virtual machines. Finally, security checking and enforcement is an integral part of each virtual machine implementation and is performed without any hardware barriers between potentially malicious applications and system code, consequently making virtual machines prone to security breaches. We observe that these problems of cost, performance, management and security stem fundamentally from the internal architecture of modern virtual machines.; This dissertation addresses the problems of cost, performance, management and security found in modern virtual machine systems. It makes four contributions. First, it introduces a new, distributed architecture for virtual machines that factors services out of endpoints into dedicated network servers. This simplifies administration through centralization, provides strong security through physical isolation and enables small, cheap and fast clients through service partitioning. Second, it proposes a methodology for structuring existing virtual machine services under this distributed service architecture. Third, this dissertation demonstrates that the proposed system architecture enables a new class of services based on secure computational platforms distributed inside a network. Finally, this thesis describes practical and effective assurance techniques for virtual machine components, such as verifiers, compilers and interpreters. These four contributions are demonstrated in the context of a commercial-grade virtual machine operating system, the Java virtual machine. Overall, these techniques address the problems in current virtual machine systems and lead to secure, manageable and efficient virtual machine systems for large networks.
机译:本文主要研究构建,构建和测试虚拟机。虚拟机系统之所以引人注目,是因为它们同时承诺可扩展性,性能和安全性。它们可以在存在不受信任的应用程序的情况下保证系统完整性,提供统一的接口并允许资源有效地实现。尽管这些功能使现代虚拟机引人注目,但当前最先进的虚拟机实现遭受与资源消耗,可管理性和安全性相关的基本问题。现有虚拟机执行它们在本地依赖的所有服务,因此在每个客户端上都需要过多的资源。另外,虚拟机在每个客户端上都包含大量状态,因此使管理大型虚拟机网络变得困难。最后,安全检查和实施是每个虚拟机实施的组成部分,并且在潜在的恶意应用程序和系统代码之间没有任何硬件障碍的情况下执行,因此使虚拟机易于出现安全漏洞。我们注意到,这些成本,性能,管理和安全性问题基本上源于现代虚拟机的内部体系结构。本文解决了现代虚拟机系统中存在的成本,性能,管理和安全性问题。它做出了四个贡献。首先,它为虚拟机引入了一种新的分布式架构,该架构将服务从端点引入专用网络服务器。这通过集中简化了管理,通过物理隔离提供了强大的安全性,并通过服务分区实现了小型,廉价和快速的客户端。其次,它提出了一种在这种分布式服务体系结构下构造现有虚拟机服务的方法。第三,本文证明了所提出的系统架构基于网络内部分布的安全计算平台,实现了一类新的服务。最后,本文描述了针对虚拟机组件(例如验证器,编译器和解释器)的实用有效的保证技术。在商业级虚拟机操作系统Java虚拟机的上下文中演示了这四个方面。总体而言,这些技术解决了当前虚拟机系统中的问题,并导致用于大型网络的安全,可管理和高效的虚拟机系统。

著录项

  • 作者

    Sirer, Emin Gun.;

  • 作者单位

    University of Washington.;

  • 授予单位 University of Washington.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2002
  • 页码 144 p.
  • 总页数 144
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号