vmOS: A virtualization-based, secure desktop system

被引:3
|
作者
Liang, Hongliang [1 ]
Li, Mingyu [1 ]
Xu, Jian [1 ]
Hu, Wenying [1 ]
Pei, Xiaoxiao [1 ]
Jia, Xiaodong [1 ]
Song, Yan [1 ]
机构
[1] Beijing Univ Posts & Telecommun, Beijing 100088, Peoples R China
基金
中国国家自然科学基金;
关键词
Hardware virtualization; Virtual machine isolation; Mandatory access control; Secure desktop system; Qemu; KVM;
D O I
10.1016/j.cose.2016.10.008
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Centralized management is typically applied in modern operating system (OS) architecture; however, such systems are prone to crash when any certain component of the OS is explicitly damaged. The basic reason is that these OSes can rarely support a thoroughly secure or isolated environment either between OS kernel-mode components or between user mode softwares. To mitigate this issue, we propose vmOS, an operating system that aims at improving the security of desktop computing environment. vmOS applies isolation technique to reduce attack surface, virtualization and mandatory access control to provide isolated environment among system components, application software and user privacy. We implement vmOS by adopting hardware-supported virtualization technology and modifying several well-known open source softwares, which aim to provide run-time efficiency of integrated system. Finally, we evaluate the security and performance by some vulnerability exploits and benchmark tools, showing that vmOS is capable of assuring the overall security of users' desktop computing with less overhead. (C) 2016 Elsevier Ltd. All rights reserved.
引用
收藏
页码:329 / 343
页数:15
相关论文
共 50 条
  • [1] Secure cryptographic functions via virtualization-based outsourced computing
    Qiang, Weizhong
    Zhang, Kang
    Dai, Weiqi
    Jin, Hai
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2016, 28 (11): : 3149 - 3163
  • [2] Providing Virtualization-based Single System Image on Clusters
    Peng, Jinbing
    Long, Xiang
    Xiao, Limin
    [J]. GCC 2008: Seventh International Conference on Grid and Cooperative Computing, Proceedings, 2008, : 28 - 32
  • [3] A Virtualization-Based Hybrid Storage System for a Map-Reduce Framework
    Dereje Tekilu, Aseffa
    Wu, Chin-Hsien
    [J]. IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2016, E99D (09): : 2248 - 2258
  • [4] A virtual time system for virtualization-based network emulations and simulations
    Zheng, Y.
    Nicol, D. M.
    Jin, D.
    Tanaka, N.
    [J]. JOURNAL OF SIMULATION, 2012, 6 (03) : 205 - 213
  • [5] A Virtualization-Based Approach for Application Whitelisting
    Tian, Donghai
    Xue, Jingfeng
    Hu, Changzhen
    Li, Xuanya
    [J]. IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2014, E97D (06): : 1648 - 1651
  • [6] An Energy-Efficient Virtualization-Based Secure Platform for Protecting Sensitive User Data
    Lim, Kyung-Soo
    Park, Jinho
    Park, Jong Hyuk
    [J]. SUSTAINABILITY, 2017, 9 (07)
  • [7] Efficient Virtualization-Based Fault Tolerance
    Tsao, Po-Jui
    Sun, Yi-feng
    Chen, Li-Han
    Cho, Chuan-Yu
    [J]. 2016 INTERNATIONAL COMPUTER SYMPOSIUM (ICS), 2016, : 114 - 119
  • [8] Virtualization-based Cognitive Radio Networks
    Al-Ayyoub, Mahmoud
    Jararweh, Yaser
    Doulat, Ahmad
    Salameh, Haythem A. Bany
    Al Aziz, Ahmad Al Abed
    Alsmirat, Mohammad
    Khreishah, Abdallah A.
    [J]. JOURNAL OF SYSTEMS AND SOFTWARE, 2016, 117 : 15 - 29
  • [9] A Virtualization-Based Business Process Management Model for Emergency Response System
    Yang Feng
    Zhao Zhikun
    Zhao Huaijin
    Yang Xiaohong
    [J]. 2009 ISECS INTERNATIONAL COLLOQUIUM ON COMPUTING, COMMUNICATION, CONTROL, AND MANAGEMENT, VOL III, 2009, : 94 - 97
  • [10] VCCP: A Transparent, Coordinated Checkpointing System for Virtualization-based Cluster Computing
    Ong, Hong
    Saragol, Natthapol
    Chanchio, Kasidit
    Leangsuksun, Chokchai
    [J]. 2009 IEEE INTERNATIONAL CONFERENCE ON CLUSTER COMPUTING AND WORKSHOPS, 2009, : 116 - +