...
首页> 外文期刊>Operating systems review >A Layered Approach to Simplified Access Control in Virtualized Systems
【24h】

A Layered Approach to Simplified Access Control in Virtualized Systems

机译:虚拟化系统中简化访问控制的分层方法

获取原文
获取原文并翻译 | 示例
           

摘要

In this work, we show how the abstraction layer created by a hypervisor, or virtual machine monitor, can be leveraged to reduce the complexity of mandatory access control policies throughout the system. Policies governing access control decisions in today's systems are complex and monolithic. Achieving strong security guarantees often means restricting usability across the entire system, which is a primary reason why mandatory access controls are rarely deployed. Our architecture uses a hypervisor and multiple virtual machines to decompose policies into multiple layers. This simplifies the policies and their enforcement, while minimizing the overall impact of security on the system. We show that the overhead of decomposing system policies into distinct policies for each layer can be negligible. Our initial implementation confirms that such layering leads to simpler security policies and enforcement mechanisms as well as a more robust layered trusted computing base. We hope that this work serves to start a dialog regarding the use of mandatory access controls within a hypervisor for both increasing security and improving manageability.
机译:在这项工作中,我们展示了如何利用虚拟机监控程序或虚拟机监视器创建的抽象层来降低整个系统中强制访问控制策略的复杂性。当今系统中用于管理访问控制决策的策略是复杂且单一的。获得强大的安全保证通常意味着限制整个系统的可用性,这是很少部署强制性访问控制的主要原因。我们的体系结构使用虚拟机管理程序和多个虚拟机将策略分解为多个层。这简化了策略及其实施,同时最大程度地降低了安全性对系统的总体影响。我们表明,将系统策略分解为每一层的不同策略的开销可以忽略不计。我们的最初实现确认,这种分层可以导致更简单的安全策略和实施机制,以及更强大的分层可信计算基础。我们希望这项工作有助于启动有关在虚拟机管理程序中使用强制访问控制的对话,以提高安全性和改善可管理性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号