首页> 外文期刊>IBM Journal of Research and Development >Secure yet usable: Protecting servers and Linux containers
【24h】

Secure yet usable: Protecting servers and Linux containers

机译:安全但可用:保护服务器和Linux容器

获取原文
获取原文并翻译 | 示例
           

摘要

Many computer security systems are considered a burden. Their inherent intrusiveness may often have an impact on the overall system stability and may conflict with a continuous stream of updates to a server operating system and components. Additionally, their complexity, and the lack of sufficient understanding of how to operate them efficiently, leads to subpar utilization of their full potential. We claim that a computer security system must make usability one of its top priorities, arguably the first, to have any chance of being correctly and fully used. In this paper, we describe Starlight, a protection tool that has usability as its core trait. We discuss the tradeoffs between security and usability and how we addressed them. Starlight monitors the behavior of a running system and creates a customized security policy, a set of operating system execution rules that accurately defines the execution boundaries of the system. We demonstrate the capabilities of our system to protect the runtime environments of servers with Linux ® containers, which add kernel exploits risks via exposure to vulnerable or rogue applications.
机译:许多计算机安全系统被认为是负担。它们固有的侵入性通常可能会影响整个系统的稳定性,并且可能与对服务器操作系统和组件的连续更新流产生冲突。此外,它们的复杂性以及对如何有效地操作它们的不足的了解,导致其潜能的利用不足。我们声称,计算机安全系统必须使可用性成为其首要任务之一,可以说是头等大事,以便有机会被正确和充分地利用。在本文中,我们描述了以实用性为核心特征的保护工具Starlight。我们讨论了安全性和可用性之间的权衡以及我们如何解决它们。 Starlight监视正在运行的系统的行为,并创建自定义的安全策略,这是一组操作系统执行规则,可准确定义系统的执行边界。我们演示了系统保护具有Linux®容器的服务器的运行时环境的功能,该功能通过暴露于易受攻击的应用程序或恶意应用程序而增加了内核利用风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号