论文标题

分析虚拟化计算系统中的流安全性属性

Analysing Flow Security Properties in Virtualised Computing Systems

论文作者

Mu, Chunyan

论文摘要

本文研究了从形式语言的角度来源的虚拟计算网络中有关流动性属性推理的问题。我们提出了一个分布式过程代数csp_ {4v},并使用安全标记的过程进行虚拟化计算系统的正式建模。具体而言,信息泄漏可能来自对过程执行,通信和虚拟环境中的缓存侧渠道的观察。我们描述了一个缓存流策略以识别此类流程。提出了该语言的类型系统,以实施流程策略并控制通过观察访问共享存储器缓存过程中虚拟机(VM)实例的交流过程和行为的行为所引入的泄漏。

This paper studies the problem of reasoning about flow security properties in virtualised computing networks with mobility from perspective of formal language. We propose a distributed process algebra CSP_{4v} with security labelled processes for the purpose of formal modelling of virtualised computing systems. Specifically, information leakage can come from observations on process executions, communications and from cache side channels in the virtualised environment. We describe a cache flow policy to identify such flows. A type system of the language is presented to enforce the flow policy and control the leakage introduced by observing behaviours of communicating processes and behaviours of virtual machine (VM) instances during accessing shared memory cache.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源