论文标题

旨在评估隔离属性以分区管理程序

Towards Assessing Isolation Properties in Partitioning Hypervisors

论文作者

Cesarano, Carmine, Cotroneo, Domenico, De Simone, Luigi

论文摘要

分区管理程序解决方案变得越来越流行,以确保与共同托管应用程序之间的隔离相关的严格安全和安全要求,并更有效地利用可用的硬件资源。但是,隔离要求的评估和认证仍然是一个挑战,了解什么以及如何测试以验证这些属性并不是一件容易的事。尽管在不同的安全性和安全相关的标准中提到了要验证的高级要求,但对于评估人员来说,缺乏精确的准则。该指南应全面,可以推广到实施分区的不同产品,并专门针对低级要求。这项工作的目的是提供一个系统的框架来满足这一需求。

Partitioning hypervisor solutions are becoming increasingly popular, to ensure stringent security and safety requirements related to isolation between co-hosted applications and to make more efficient use of available hardware resources. However, assessment and certification of isolation requirements remain a challenge and it is not trivial to understand what and how to test to validate these properties. Although the high-level requirements to be verified are mentioned in the different security- and safety-related standards, there is a lack of precise guidelines for the evaluator. This guidance should be comprehensive, generalizable to different products that implement partitioning, and tied specifically to lower-level requirements. The goal of this work is to provide a systematic framework that addresses this need.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源