Hypervisors for Security and Robustness
Abstract
This is the final report for the Hypervisors for Security and Robustness (Kernel Hypervisors) program. It contains a description of the kernel hypervisor approach that was developed on the program for selectively controlling COTS components to provide robustness and security. Using the concept of a loadable module, kernel hypervisors were implemented on a Linux kernel. These kernel hypervisors provide unbypassable security wrappers for application specific security requirements and can also be used to provide replication services. Kernel hypervisors have a number of potential applications, including protecting user systems from malicious active content downloaded via a Web browser and wn%ping servers and firewall services for limiting possible compromises. This report also includes a summary of the results of the performance testing and composability analysis that was done on the program. It concludes with a discussion of lessons learned and open issues.
Document Details
- Document Type
- Technical Report
- Publication Date
- Feb 01, 1999
- Accession Number
- ADA360460
Entities
People
- Brian Loe
- Dick O'brien
- Kent Larson
- Raymond Lu
- Terrence Mitchum