A separation model for virtual machine monitors

N. Kelem, R. Feiertag
{"title":"A separation model for virtual machine monitors","authors":"N. Kelem, R. Feiertag","doi":"10.1109/RISP.1991.130776","DOIUrl":null,"url":null,"abstract":"A security policy is given for separation virtual machine monitors (SVMMs) and the authors interpret J.M. Rushby's (1981) separation model for SVMMs. Applying Rushby's technique yields a practical method for demonstrating that an implementation of an SVMM adheres to the abstract isolation axiom of the separation model, thus providing relatively strong assurance for a low level of effort. The authors describe the relevant characteristics of SVMMs and note the applicable formal modeling requirements. A summary of the SVMM separation model, which is a modification of the original model presented by Rushby, is given. The separation model technique permits a proof of separability among the operating systems under control of the kernel of an SVMM. An interpretation of the elements of the separation model using concepts from SVMMs is given.<<ETX>>","PeriodicalId":445112,"journal":{"name":"Proceedings. 1991 IEEE Computer Society Symposium on Research in Security and Privacy","volume":"236 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1991-05-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"42","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings. 1991 IEEE Computer Society Symposium on Research in Security and Privacy","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/RISP.1991.130776","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 42

Abstract

A security policy is given for separation virtual machine monitors (SVMMs) and the authors interpret J.M. Rushby's (1981) separation model for SVMMs. Applying Rushby's technique yields a practical method for demonstrating that an implementation of an SVMM adheres to the abstract isolation axiom of the separation model, thus providing relatively strong assurance for a low level of effort. The authors describe the relevant characteristics of SVMMs and note the applicable formal modeling requirements. A summary of the SVMM separation model, which is a modification of the original model presented by Rushby, is given. The separation model technique permits a proof of separability among the operating systems under control of the kernel of an SVMM. An interpretation of the elements of the separation model using concepts from SVMMs is given.<>
虚拟机监视器的分离模型
给出了分离虚拟机监视器(svm)的安全策略,并对J.M. Rushby(1981)的svm分离模型进行了解释。应用Rushby的技术产生了一种实用的方法,用于证明支持向量机的实现遵循分离模型的抽象隔离公理,从而为低水平的工作提供了相对强大的保证。作者描述了svm的相关特征,并指出了适用的形式化建模需求。对Rushby提出的支持向量机分离模型进行了改进,并对该模型进行了总结。分离模型技术允许在支持向量机内核控制下的操作系统之间证明可分离性。使用支持向量机的概念对分离模型的元素进行了解释。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信