亚洲av成人无遮挡网站在线观看,少妇性bbb搡bbb爽爽爽,亚洲av日韩精品久久久久久,兔费看少妇性l交大片免费,无码少妇一区二区三区

  免費(fèi)注冊(cè) 查看新帖 |

Chinaunix

  平臺(tái) 論壇 博客 文庫(kù)
最近訪問(wèn)板塊 發(fā)新帖
查看: 1886 | 回復(fù): 0
打印 上一主題 下一主題

Xen中的訪問(wèn)控制以及安全策略介紹 [復(fù)制鏈接]

論壇徽章:
0
跳轉(zhuǎn)到指定樓層
1 [收藏(0)] [報(bào)告]
發(fā)表于 2011-12-20 09:47 |只看該作者 |倒序?yàn)g覽
本文不會(huì)對(duì)Xen的安全實(shí)現(xiàn)進(jìn)行深入的描述,只簡(jiǎn)單列出了Xen中采用IBM研究中心實(shí)現(xiàn)的安全框架的功能,其絕大部分直接來(lái)至IBM的相關(guān)網(wǎng)頁(yè),即:http://domino.research.ibm.com/comm/research_projects.nsf/pages/ssd_shype.index.html,訪問(wèn)網(wǎng)頁(yè)的時(shí)間是2011年3月6日晚。

Xen Hypervisor提供了一個(gè)可選的低級(jí)訪問(wèn)控制框架,該框架基于Secure Hypervisor(sHype)。提供的功能有:
     (1)允許或者拒絕資源的訪問(wèn);
     (2)運(yùn)行或者拒絕hypervisor級(jí)的域間通信。
在操作系統(tǒng)級(jí),則可以使用Linux的SELinux(網(wǎng)址:http://selinux.sourceforge.net)提供操作系統(tǒng)級(jí)的訪問(wèn)控制保護(hù)。

以下內(nèi)容摘至sHype網(wǎng)站:

The Secure Hypervisor (sHype) is a hypervisor security architecture developed by IBM Research, in various stages of implementation in several hypervisors. sHype is designed and developed in close collaboration with the IBM Systems and Technology Group. Our main goal is to provide a secure foundation for server platforms, providing functions such as:

  1. Strong isolation, mediated sharing and communication between Virtual Machines. 
    These properties are all strictly controlled by a flexible access control enforcement engine. This engine can enforce mandatory policies such as Multi-level Security (MLS), Role-based Access Control (RBAC), and Type Enforcement (TE).

  2. Attestation and integrity guarantees for the hypervisor and its virtual machines. 
    We are extending the Trusted Computing Group (TCG) specification to include hypervisor-based server platforms. Our goal here is secure boot or authenticated boot code guarantees for the hypervisor platform, Virtual Machines, and optionally the guest operating systems and applications running on Virtual Machines. To support a large number of Virtual Machines, we have developed a virtual TPM architecture which we have applied to the Xen open-source hypervisor.

  3. Resource control and accurate accounting guarantees. 
    All resources are strictly accounted for and may be constrained. Simple resources include memory and CPU cycles. More elaborate resource management is needed to control network bandwidth, e.g., to limit the network bandwidth to a Virtual Machine.

  4. Secure Services.
    sHype provides the base infrastructure for disaggregation of services, such as security policy management or distributed auditing, into smaller and more manageable protected execution environments, thereby enabling their system-wide utilization and potentially enhancing the assurance of these services.

Our work on the secure hypervisor focuses on securing IBM server platforms and we are taking advantage of IBM's high-performance virtualization support because performance is key to the acceptance of sHype. 

In the open source community, we have developed a small security extension to Xen (Xen User Guide Chapter), an open-source hypervisor. It allows administrators to define simple policies (currently: Chinese Wall and Type Enforcement) that govern the control and sharing capabilities of Virtual Machines that run simultaneously on a single Xen system. We have also explored implementing these security architecture features in the open-source Research hypervisor rHype, with Linux running inside the Virtual Machines.

Related Publications:

Reiner Sailer, Trent Jaeger, Enriquillo Valdez, Ramón Cáceres, Ronald Perez, Stefan Berger, John Griffin, Leendert van Doorn: Building a MAC-based Security Architecture for the Xen Opensource Hypervisor. 21st Annual Computer Security Applications Conference (ACSAC), December 5-9, Tucson, Arizona, 2005. (PaperSlides).

Stefan Berger, Ramón Cáceres, Kenneth Goldman, Ronald Perez, Reiner Sailer, Leendert van Doorn: vTPM: Virtualizing the Trusted Platform Module. 15th USENIX Security Symposium, July 2006, Vancouver, Canada (Paper, Draft version as IBM Research Report RC23879).

Trent Jaeger, Patrick McDaniel, Luke St. Clair, Ramón Cáceres, Reiner Sailer: Shame on Trust in Distributed Systems. HotSec'06. 1st Usenix Workshop on Hot Topics in Security. July 2006, Vancouver, Canada (Paper, Draft version as IBM Research Report RC23964).

Jonathan M McCune, Stefan Berger, Ramón Cáceres, Trent Jaeger, Reiner Sailer: Shamon -- A System for Distributed Mandatory Access Control. 22nd Annual Computer Security Applications Conference (ACSAC), Miami Beach, Florida, December 2006 (Paper).

Xen User Guide Chapter for the Xen sHype/Access Control Module (Chapter 10).

您需要登錄后才可以回帖 登錄 | 注冊(cè)

本版積分規(guī)則 發(fā)表回復(fù)

  

北京盛拓優(yōu)訊信息技術(shù)有限公司. 版權(quán)所有 京ICP備16024965號(hào)-6 北京市公安局海淀分局網(wǎng)監(jiān)中心備案編號(hào):11010802020122 niuxiaotong@pcpop.com 17352615567
未成年舉報(bào)專(zhuān)區(qū)
中國(guó)互聯(lián)網(wǎng)協(xié)會(huì)會(huì)員  聯(lián)系我們:huangweiwei@itpub.net
感謝所有關(guān)心和支持過(guò)ChinaUnix的朋友們 轉(zhuǎn)載本站內(nèi)容請(qǐng)注明原作者名及出處

清除 Cookies - ChinaUnix - Archiver - WAP - TOP