| G.J. Popek and C.S. Kline. Verifiable secure operating system software. In AFIPS Conference Proceedings, June 1973. |
....to the underlying hardware is simpler to build and more robust. We are intrigued by the possibility of using transparent instruction set mapping, as is done on the Transmeta Crusoe processor. 6. 3 Small kernel architectures VMMs have served as the foundation of several security kernels [26, 31, 35]. More recently, the NetTop initiative has sought to create secure virtual workstations running on VMWare [40] Our work di#ers from these e#orts in that we aim to provide scalability as well as isolation. Our work also assumes a weaker threat model: we are not concerned with covert channels ....
G.J. Popek and C.S. Kline. Verifiable secure operating system software. In AFIPS Conference Proceedings, June 1973.
....features and runtime verification and control. However, Java requires the use of a special language, and recently uncovered bugs have demonstrated that the implementation of the runtime security mechanisms is error prone. Virtualmachines can provide strong isolation guarantees between subsystems[41], addressing denial of service attacks and informationleaks throughcovert channels as well as providing a clean separation between different pieces of mobile code (Applets) Such isolation can also be useful for resource reservation, such as guaranteeing a certain amount of physical memory to ....
G. J. Popek and C. Kline. Verifiable secure operating systems software. In AFIPS Conf. Proc., June 1973.
....the security manager, and (iii) can provide strong resource accounting and control. We elaborate on these features below. Our proposed use of virtual machines for security is well established: one of the uses of classic virtual machines was to provide isolation guarantees between subsystems [22]. However, we also provide the ability to nest virtual machines, and that is important for worldwide applications. A machine that runs untrusted applications requires a number of features from its operating system. It needs the ability to, by default, isolate the untrusted environment from the ....
G. J. Popek and C. Kline. Verifiable Secure Operating Systems Software. In AFIPS Conf. Proc., June 1973.
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC