Cerberus: A Novel Hypervisor to Provide Trusted and Isolated Code Execution

Wenzhi Chen, Zhipeng Zhang, Jian-Hua Yang, Qin-Ming He
{"title":"Cerberus: A Novel Hypervisor to Provide Trusted and Isolated Code Execution","authors":"Wenzhi Chen, Zhipeng Zhang, Jian-Hua Yang, Qin-Ming He","doi":"10.1109/ISME.2010.172","DOIUrl":null,"url":null,"abstract":"Cerberus is a tiny x86 virtual machine monitor. It allows security sensitive codes to be executed in an isolated circumstance. The codes could attest their integrity to a remote party by a two-step attestation provided by Cerberus. Cerberus does not require the security sensitive applications to be modified or recompiled to run on it. These applications are packaged with the operating systems as virtual appliances (VA). The on-disk VA files are read-only to simplify the attestation process. Any storage file is sealed to the corresponding secure domain. Cerberus leveraged the nested paging technology to isolate the memory regions efficiently. And it also introduced a novel secure display sharing technology. It can guarantee the security property even when the attackers get control of everything but the core hardware infrastructures. Our performance experiment results show that the overhead introduced by Cerberus is less than 5%.","PeriodicalId":348878,"journal":{"name":"2010 International Conference of Information Science and Management Engineering","volume":"212 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2010-08-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2010 International Conference of Information Science and Management Engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISME.2010.172","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

Cerberus is a tiny x86 virtual machine monitor. It allows security sensitive codes to be executed in an isolated circumstance. The codes could attest their integrity to a remote party by a two-step attestation provided by Cerberus. Cerberus does not require the security sensitive applications to be modified or recompiled to run on it. These applications are packaged with the operating systems as virtual appliances (VA). The on-disk VA files are read-only to simplify the attestation process. Any storage file is sealed to the corresponding secure domain. Cerberus leveraged the nested paging technology to isolate the memory regions efficiently. And it also introduced a novel secure display sharing technology. It can guarantee the security property even when the attackers get control of everything but the core hardware infrastructures. Our performance experiment results show that the overhead introduced by Cerberus is less than 5%.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Cerberus:一种提供可信和隔离代码执行的新型管理程序
Cerberus是一个小型的x86虚拟机监视器。它允许在孤立的环境中执行安全敏感代码。代码可以通过Cerberus提供的两步认证向远程方证明其完整性。Cerberus不需要修改或重新编译安全敏感的应用程序来运行。这些应用程序作为虚拟设备(VA)打包在操作系统中。磁盘上的VA文件是只读的,以简化认证过程。任何存储文件都被密封到相应的安全域。Cerberus利用嵌套分页技术有效地隔离内存区域。介绍了一种新型的安全显示共享技术。即使攻击者控制了除核心硬件基础设施以外的一切,它也能保证系统的安全性。我们的性能实验结果表明,Cerberus引入的开销小于5%。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Research on Construction Strategy of Enterprise Information Sharing in Supply Chain Mond-Weir Type Duality in Nondifferentiable Fractional Programming with Generalized Convexity A Bin-packing Model Based on File Preservation Problem Comprehensive Evaluation Based on Gray Relation Analysis for Information Security Management Measurement A Model on Customer Satisfaction Degree Evaluation of Third Party Logistics
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1