DocumentCode :
3334484
Title :
Using kernel hypervisors to secure applications
Author :
Mitchem, Terrence ; Lu, Raymond ; Brien, Richard O.
Author_Institution :
Secure Comput. Corp., Roseville, MN, USA
fYear :
1997
fDate :
8-12 Dec 1997
Firstpage :
175
Lastpage :
181
Abstract :
The paper describes an approach for selectively controlling COTS components to provide robustutess and security. Using the concept of a loadable module, “kernel hypervisors” have been implemented on a Linux kernel. These kernel hypervisors provide unbypassable security wrappers for application specific security requirements and can be used to provide replication services as well. A framework has been developed based on a master kernel hypervisor whose job is to coordinate installation and removal of individual client kernel hypervisors and to provide a means for management of these clients. The framework allows client kernel hypervisors to be stacked so that a variety of application specific policies can be implemented, each by means of its own kernel hypervisor. The hypervisors run in the kernel, but since they are loadable modules, they do not require that the kernel be modified. Kernel hypervisors have a number of potential applications, including protecting user systems from malicious active content downloaded via a Web browser and wrapping servers and firewall services for limiting possible compromises
Keywords :
client-server systems; operating system kernels; security of data; software fault tolerance; COTS components; Linux kernel; Web browser; application specific policies; application specific security requirements; client kernel hypervisors; firewall services; kernel hypervisors; loadable module; loadable modules; malicious active content; replication services; secure applications; selective control; unbypassable security wrappers; user systems; wrapping servers; Hardware; Kernel; Lakes; Linux; Monitoring; Protection; Robustness; Security; Virtual machine monitors; Wrapping;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Security Applications Conference, 1997. Proceedings., 13th Annual
Conference_Location :
San Diego, CA
ISSN :
1063-9527
Print_ISBN :
0-8186-8274-4
Type :
conf
DOI :
10.1109/CSAC.1997.646188
Filename :
646188
Link To Document :
بازگشت