...
首页> 外文期刊>Journal of Computers >Secure-Turtles: Building a Secure Execution Environment for Guest VMs on Turtles System
【24h】

Secure-Turtles: Building a Secure Execution Environment for Guest VMs on Turtles System

机译:安全乌龟:为乌龟系统上的Guest虚拟机构建安全的执行环境

获取原文
           

摘要

—We propose Secure-Turtle, a secure nested virtual system based on Turtles system, which provides a secure execution environment for the L2 guest VM. In particular, Secure-Turtles system builds a trust chain from L0 host hypervisor, L1 guest hypervisor, qemu-kvm daemon to L2 guest VM. Through this security chain, Secure-Turtles can protect L2 guest VM against attacks form the L1 user mode, even when the attacker has the root privilege of the L1 guest hypervisor. Our goal is to make Secure-Turtles possible to rule out known class of vulnerabilities from the L1 user. We proposed four general requirements for Secure-Turtles to satisfy to achieve our goal and list sixteen basic properties for the Secure-Turtles system to achieve. With these properties, the proposed four requirements can be guaranteed. We rely on the memory virtualization to build Secure-Turtles and implement a prototype based on Turtles. We evaluate its prototype using two metrics: security and performance. The security evaluation result shows that Secure-Turtles can protect L2 guest VM from attacks from the L1 user mode. The performance result shows that Secure-Turtles introduces little performance overhead to the L2 guest VM compared with the Turtles system.
机译:- 我们提出了一个基于乌龟系统的安全嵌套虚拟系统的安全龟,为L2 Guest VM提供了安全的执行环境。特别是,安全龟系统从L0主机管理程序,L1 Guest虚拟机管理程序,QEMU-KVM守护程序到L2 Guest VM的信任链。通过这种安全链,即使攻击者具有L1 Guest虚拟机管理程序的root权限,安全海龟也可以保护L2 Guest VM免受攻击攻击。我们的目标是使安全龟可以从L1用户排队出了已知的漏洞。我们提出了四个安全海龟的一般要求,以满足实现目标和列出安全龟系统的十六个基本属性。通过这些属性,可以保证提出的四种要求。我们依靠内存虚拟化来构建安全龟并基于乌龟实现原型。我们使用两个度量评估其原型:安全性和性能。安全性评估结果表明,安全海龟可以保护L2 Guest VM免受L1用户模式的攻击。性能结果表明,与乌龟系统相比,安全海龟对L2 Guest VM的性能很少。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号