论文标题

使用虚拟化技术从脆弱的应用中拯救最终用户系统

Rescuing the End-user systems from Vulnerable Applications using Virtualization Techniques

论文作者

Trivedi, Vinayak, Gurjar, Tushar, Shaikh, Sumaiya, Maddamsetty, Saketh, Mishra, Debadatta

论文摘要

在普通最终用户拥有的系统中,许多次通过在恶意应用程序中潜行或通过用户的安全不合格操作来利用现有软件漏洞来安装安全攻击。虚拟化方法可以通过为应用程序,恶意设备和设备驱动程序提供隔离环境来解决此问题,这些环境主要用作安全攻击的入口点。但是,在应用程序接口透明度和文件系统透明度方面,使用虚拟化提供隔离环境的现有方法对用户不透明。此外,软件配置级别解决方案(例如远程台式机和远程应用程序访问机制与共享文件系统结合使用)不符合用户透明度和安全要求。我们提出了QoS,一种基于VM的解决方案与某些操作系统扩展相结合,以透明和高效的方式满足普通用户拥有的终点系统的安全要求。我们通过经验评估Linux+KVM系统中的原型实现,以效率,安全性和用户透明度来证明QoS的功效。

In systems owned by normal end-users, many times security attacks are mounted by sneaking in malicious applications or exploiting existing software vulnerabilities through security non-conforming actions of users. Virtualization approaches can address this problem by providing a quarantine environment for applications, malicious devices, and device drivers, which are mostly used as entry points for security attacks. However, the existing methods to provide quarantine environments using virtualization are not transparent to the user, both in terms of application interface transparency and file system transparency. Further, software configuration level solutions like remote desktops and remote application access mechanisms combined with shared file systems do not meet the user transparency and security requirements. We propose qOS, a VM-based solution combined with certain OS extensions to meet the security requirements of end-point systems owned by normal users, in a transparent and efficient manner. We demonstrate the efficacy of qOS by empirically evaluating the prototype implementation in the Linux+KVM system in terms of efficiency, security, and user transparency.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源