TAILIEUCHUNG - Labels and Event Processes in the Asbestos Operating System

Key elements of successful programmes Key elements of successful WHP programmes include: establishing clear goals and objectives, linking programmes to business objectives; strong management support; effective communication with, and involvement of, employees at all levels of development and implementation of the WHP programme; creating supportive environments; adapting the programme to social norms and building social support; considering incentives to foster adherence to the programmes and improving self-efficacy of the participants. . | Labels and Event Processes in the Asbestos Operating System STEVE VANDEBOGART PETROS EFSTATHOPOULOS and EDDIE KOHLER University of California Los Angeles MAXWeLl KROHN CLIFF FREY DAVID ZIEGLER FRANS KAASHOEK and ROBERT MORRIS Massachusetts Institute of Technology and DAVID MAZIERES Stanford University 11 Asbestos a new operating system provides novel labeling and isolation mechanisms that help contain the effects of exploitable software flaws. Applications can express a wide range of policies with Asbestos s kernel-enforced labels including controls on interprocess communication and systemwide information flow. A new event process abstraction defines lightweight isolated contexts within a single process allowing one process to act on behalf of multiple users while preventing it from leaking any single user s data to others. A Web server demonstration application uses these primitives to isolate private user data. Since the untrusted workers that respond to client requests are constrained by labels exploited workers cannot directly expose user data except as allowed by application policy. The server application requires memory pages per user for up to 145 000 users and achieves connection rates similar to Apache demonstrating that additional security can come at an acceptable cost. Categories and Subject Descriptors Operating Systems Security and Protection Information flow controls Access controls Operating Systems Process Management Operating Systems Organization and Design Computer System Implementation Servers General Terms Security Design Performance Additional Key Words and Phrases Information flow labels mandatory access control process abstractions secure Web servers This work was supported by DARPA grants MDA972-03 and FA8750-04-1-0090 and by joint NSF Cybertrust DARPA grant CNS-0430425. E. Kohler D. Mazieres and R. Morris are supported by Sloan fellowships. E. Kohler is also supported by a Microsoft Research New Faculty .

TAILIEUCHUNG - Chia sẻ tài liệu không giới hạn
Địa chỉ : 444 Hoang Hoa Tham, Hanoi, Viet Nam
Website : tailieuchung.com
Email : tailieuchung20@gmail.com
Tailieuchung.com là thư viện tài liệu trực tuyến, nơi chia sẽ trao đổi hàng triệu tài liệu như luận văn đồ án, sách, giáo trình, đề thi.
Chúng tôi không chịu trách nhiệm liên quan đến các vấn đề bản quyền nội dung tài liệu được thành viên tự nguyện đăng tải lên, nếu phát hiện thấy tài liệu xấu hoặc tài liệu có bản quyền xin hãy email cho chúng tôi.
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.