首页> 外文OA文献 >Salus: Non-hierarchical memory access rights to enforce the principle of least privilege
【2h】

Salus: Non-hierarchical memory access rights to enforce the principle of least privilege

机译:Salus:非分层内存访问权限,用于强制执行最小特权原则

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Consumer devices are increasingly being used to perform security and privacy critical tasks. The software used to perform these tasks is often vulnerable to attacks, due to bugs in the application itself or in included software libraries. Recent work proposes the isolation of security-sensitive parts of applications into protected modules, each of which can only be accessed through a predefined public interface. But most parts of an application can be considered security-sensitive at some level, and an attacker that is able to gain in-application level access may be able to abuse services from protected modules.We propose Salus, a Linux kernel modification that provides a novel approach for partitioning processes into isolated compartments. By enabling compartments to restrict the system calls they are allowed to perform and to authenticate their callers and callees, the impact of unsafe interfaces and vulnerable compartments is significantly reduced. We describe the design of Salus, report on a prototype implementation and evaluate it in terms of security and performance. We show that Salus provides a significant security improvement with a low performance overhead, without relying on any non-standard hardware support.
机译:消费类设备越来越多地用于执行安全和隐私关键任务。由于应用程序本身或随附软件库中的错误,用于执行这些任务的软件通常容易受到攻击。最近的工作提出将应用程序的安全敏感部分隔离到受保护的模块中,每个模块只能通过预定义的公共接口进行访问。但是应用程序的大多数部分在某种程度上被认为是安全敏感的,能够获得应用程序内访问权限的攻击者可能会滥用受保护模块的服务。我们建议使用Salus,这是Linux内核的一种修改,它提供了将过程划分为隔离的隔离区的新颖方法。通过启用隔离专区来限制允许他们执行的系统调用并验证其呼叫者和被叫方的身份,可以显着减少不安全接口和易损隔离专区的影响。我们描述Salus的设计,报告原型实现并在安全性和性能方面进行评估。我们证明Salus在不依赖任何非标准硬件支持的情况下,以较低的性能开销提供了显着的安全性改进。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号