Sego: Pervasive Trusted Metadata For Efficiently Verified Untrusted System Services

ACM SIGPLAN Notices(2016)

引用 52|浏览158
暂无评分
摘要
Sego is a hypervisor-based system that gives strong privacy and integrity guarantees to trusted applications, even when the guest operating system is compromised or hostile. Sego verifies operating system services, like the file system, instead of replacing them. By associating trusted metadata with user data across all system devices, Sego verifies system services more efficiently than previous systems, especially services that depend on data contents. We extensively evaluate Sego's performance on real workloads and implement a kernel fault injector to validate Sego's file systemagnostic crash consistency and recovery protocol.
更多
查看译文
关键词
Security,Verification,Application protection,Virtualization-based security,Paraverification,Crash consistency
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要