首页> 外文期刊>ACM Transaction on Information and System Security >Safe and Efficient Implementation of a Security System on ARM using Intra-level Privilege Separation
【24h】

Safe and Efficient Implementation of a Security System on ARM using Intra-level Privilege Separation

机译:使用级别内特权分离在ARM上安全有效地实现安全系统

获取原文
获取原文并翻译 | 示例

摘要

Security monitoring has long been considered as a fundamental mechanism to mitigate the damage of a security attack. Recently, intra-level security systems have been proposed that can efficiently and securely monitor system software without any involvement of more privileged entity. Unfortunately, there exists no full intra-level security system that can universally operate at any privilege level on ARM. However, as malware and attacks increase against virtually every level of privileged software including an OS, a hypervisor, and even the highest privileged software armored by TrustZone, we have been motivated to develop an intra-level security system, named Hilps. Hilps realizes true intra-level scheme in all these levels of privileged software on ARM by elaborately exploiting a new hardware feature of ARM's latest 64-bit architecture, called TxSZ, that enables elastic adjustment of the accessible virtual address range. Furthermore, Hilps newly supports the sandbox mechanism that provides security tools with individually isolated execution environments, thereby minimizing security threats from untrusted security tools. We have implemented a prototype of Hilps on a real machine. The experimental results demonstrate that Hilps is quite promising for practical use in real deployments.
机译:长期以来,安全监视一直被认为是减轻安全攻击损害的基本机制。近来,已经提出了可以在不涉及更多特权实体的情况下有效且安全地监视系统软件的层内安全系统。不幸的是,不存在可以在ARM上的任何特权级别普遍运行的完整的内部安全系统。但是,随着恶意软件和攻击几乎对包括操作系统,系统管理程序以及TrustZone装甲的最高特权软件在内的每个特权软件级别的增加,我们受到了开发名为Hilps的内部安全系统的激励。 Hilps通过精心利用ARM最新的64位体系结构(称为TxSZ)的新硬件功能,实现了所有这些级别的ARM特权软件上的真正的内部方案,该弹性功能可灵活调整可访问的虚拟地址范围。此外,Hilps新支持沙盒机制,该沙盒机制为安全工具提供了单独隔离的执行环境,从而最大程度地减少了不受信任的安全工具带来的安全威胁。我们已经在实际机器上实现了Hilps的原型。实验结果表明,Hilps在实际部署中具有实际应用前景。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号