Building a mac-based security architecture for the Xen open-source hypervisor


Download 220.31 Kb.
Pdf ko'rish
bet8/16
Sana15.06.2023
Hajmi220.31 Kb.
#1486893
1   ...   4   5   6   7   8   9   10   11   ...   16
Bog'liq
Building a MAC based security architecture for the Xen open source

4.3.1 Reference Monitor
sHype strictly separates access control enforcement from
the access control policy, as in the Flask [33] architecture.
5
Proceedings of the 21st Annual Computer Security Applications Conference (ACSAC 2005) 
1063-9527/05 $20.00 © 2005 IEEE 
Authorized licensed use limited to: Tashkent University of Information Technologies. Downloaded on April 06,2023 at 09:07:42 UTC from IEEE Xplore. Restrictions apply. 


VM
(Subject)
Hook
Object
Core Hypervisor
Access
Control
Module
1. H_Call
2. Authorization Query
3. Authorization Decision
Hypervisor
Binary
Security
Policy
Security
Policy
Manager
VM
XML
Security
Policy
Figure 4. sHype security reference monitor
We describe the control architecture in the context of the
hypervisor, but it will also be used in the MAC domains.
Figure 4 shows the sHype access control architecture as part
of the core hypervisor and depicts the relationships between
its three major design components. Security enforcement
hooks are carefully inserted into the core hypervisor and
cover references of VMs to virtual resources. Enforcement
hooks retrieve access control decisions from the access con-
trol module (ACM).
The ACM authorizes access of VMs to resources based
on the policy rules and the security labels attached to VMs
(CW-types, TE-types) and resources (TE-types). The for-
mal security policy defines these access rules as well as the
structure and interpretation of security labels for VMs and
resources. Finally, a hypervisor interface enables trusted
policy-management VMs to manage the ACM security pol-
icy.

Download 220.31 Kb.

Do'stlaringiz bilan baham:
1   ...   4   5   6   7   8   9   10   11   ...   16




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©fayllar.org 2024
ma'muriyatiga murojaat qiling