An Efficient Approach for Mitigating Covert Storage Channel Attacks in Virtual Machines by the Anti-

来源 :计算机科学技术学报(英文版) | 被引量 : 0次 | 上传用户:shylockbc
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Covert channels have been an effective means for leaking confidential information across security domains and numerous studies are available on typical covert channels attacks and defenses. Existing covert channel threat restriction solutions are based on the threat estimation criteria of covert channels such as capacity, accuracy, and short messages which are effective in evaluating the information transmission ability of a covert (storage) channel. However, these criteria cannot comprehensively reflect the key factors in the communication process such as shared resources and synchronization and therefore are unable to evaluate covertness and complexity of increasingly upgraded covert storage channels. As a solution, the anti-detection criterion was introduced to eliminate these limitations of cover channels. Though effective, most threat restriction techniques inevitably incur high performance overhead and hence become impractical. In this work, we avoid such overheads and present a restriction algorithm based on the anti-detection criterion to restrict threats that are associated with covert storage channels in virtual machines while maintaining the resource efficiency of the systems. Experimental evaluation shows that our proposed solution is able to counter covert storage channel attacks in an effective manner. Compared with Pump, a well-known traditional restriction algorithm used in practical systems, our solution significantly reduces the system overhead.
其他文献
期刊
期刊
为满足决策支持系统对桉树枝瘿姬小蜂虫害风险评估及获取量化结果的需要,根据已知桉树枝瘿姬小蜂生物学性状和传播规律,建立了桉树枝瘿姬小蜂虫害风险模糊评价体系,提出了基
期刊
期刊
九宫山自然保护区异地保存珍稀濒危植物有2种方法:株群混合栽培与模拟群落栽培。选取了16种珍稀濒危物种,经过10年观测分析,结果表明:模拟群落栽培方法比株群混合栽培方法更
近年来小儿药物中毒发病率明显增加,中毒药物的种类也不断发生变化,药源性疾病已构成影响儿童生命安全及身体健康的重要疾病。我科自2001年11月至2008年10月共收治各类药物中