vmOS: A virtualization-based, secure desktop system

被引:3
|
作者
Liang, Hongliang [1 ]
Li, Mingyu [1 ]
Xu, Jian [1 ]
Hu, Wenying [1 ]
Pei, Xiaoxiao [1 ]
Jia, Xiaodong [1 ]
Song, Yan [1 ]
机构
[1] Beijing Univ Posts & Telecommun, Beijing 100088, Peoples R China
基金
中国国家自然科学基金;
关键词
Hardware virtualization; Virtual machine isolation; Mandatory access control; Secure desktop system; Qemu; KVM;
D O I
10.1016/j.cose.2016.10.008
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Centralized management is typically applied in modern operating system (OS) architecture; however, such systems are prone to crash when any certain component of the OS is explicitly damaged. The basic reason is that these OSes can rarely support a thoroughly secure or isolated environment either between OS kernel-mode components or between user mode softwares. To mitigate this issue, we propose vmOS, an operating system that aims at improving the security of desktop computing environment. vmOS applies isolation technique to reduce attack surface, virtualization and mandatory access control to provide isolated environment among system components, application software and user privacy. We implement vmOS by adopting hardware-supported virtualization technology and modifying several well-known open source softwares, which aim to provide run-time efficiency of integrated system. Finally, we evaluate the security and performance by some vulnerability exploits and benchmark tools, showing that vmOS is capable of assuring the overall security of users' desktop computing with less overhead. (C) 2016 Elsevier Ltd. All rights reserved.
引用
收藏
页码:329 / 343
页数:15
相关论文
共 50 条
  • [31] vMobiDesk: Desktop Virtualization for Mobile Operating System
    Su, Kui
    Jiang, Pengfei
    Wang, Zonghui
    Chen, Wenzhi
    [J]. PROCEEDINGS OF 2016 IEEE 18TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS; IEEE 14TH INTERNATIONAL CONFERENCE ON SMART CITY; IEEE 2ND INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS), 2016, : 945 - 950
  • [32] Research on Virtualization-Based Video-On-Demand Services Architecture
    Shu, Chang
    Zhang, Xingming
    [J]. FOURTH INTERNATIONAL CONFERENCE ON MACHINE VISION (ICMV 2011): MACHINE VISION, IMAGE PROCESSING, AND PATTERN ANALYSIS, 2012, 8349
  • [33] Service Provisioning in Virtualization-based Cloud Computing: Modeling and Optimization
    Huang, Jun
    Liu, Yanbing
    Duan, Qiang
    [J]. 2012 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2012,
  • [34] Analysis of a Virtualization-based Recovery approach for Intrusion Tolerance Systems
    Huang, Jianhua
    Ai, Qing
    [J]. 2013 INTERNATIONAL CONFERENCE ON COMPUTER SCIENCES AND APPLICATIONS (CSA), 2013, : 41 - 46
  • [35] Fast Memory State Synchronization for Virtualization-based Fault Tolerance
    Lu, Maohua
    Chiueh, Tzi-cker
    [J]. 2009 IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS & NETWORKS (DSN 2009), 2009, : 534 - 543
  • [36] Applicability of SDN and NFV Techniques for a Virtualization-Based Roaming Solution
    Contreras, Luis M.
    Cominardi, Luca
    Martin Perez, Jorge
    Bernardos, Carlos J.
    [J]. JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2020, 28 (03) : 576 - 604
  • [37] Detection of metamorphic and virtualization-based malware using algebraic specification
    Webster, Matt
    Malcolm, Grant
    [J]. JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2009, 5 (03): : 221 - 245
  • [38] Study on Fault Tolerance for Virtualization-Based Computer Simulation Systems
    Ren, Lei
    Luo, Yongliang
    Zhang, Yabin
    [J]. ADVANCED MANUFACTURING SYSTEMS, PTS 1-3, 2011, 201-203 : 677 - 680
  • [39] Automatic Selection and Resolution Allocation in Virtualization-Based Future Internet
    Cai, Ling
    Wang, Jin-kuan
    Wang, Cong
    Wang, Xing-wei
    [J]. INTERNATIONAL CONFERENCE ON ELECTRICAL, CONTROL AND AUTOMATION ENGINEERING (ECAE 2013), 2013, : 546 - 552
  • [40] Applicability of SDN and NFV Techniques for a Virtualization-Based Roaming Solution
    Luis M. Contreras
    Luca Cominardi
    Jorge Martín Pérez
    Carlos J. Bernardos
    [J]. Journal of Network and Systems Management, 2020, 28 : 576 - 604