Authors
Reiner Sailer, Trent Jaeger, Enriquillo Valdez, Ramon Caceres, Ronald Perez, Stefan Berger, John Linwood Griffin, Leendert Van Doorn
Publication date
2005/12/5
Conference
21st Annual Computer Security Applications Conference (ACSAC'05)
Pages
10 pp.-285
Publisher
IEEE
Description
We present the sHype hypervisor security architecture and examine in detail its mandatory access control facilities. While existing hypervisor security approaches aiming at high assurance have been proven useful for high-security environments that prioritize security over performance and code reuse, our approach aims at commercial security where near-zero performance overhead, non-intrusive implementation, and usability are of paramount importance. sHype enforces strong isolation at the granularity of a virtual machine, thus providing a robust foundation on which higher software layers can enact finer-grained controls. We provide the rationale behind the sHype design and describe and evaluate our implementation for the Xen open-source hypervisor
Total citations
2005200620072008200920102011201220132014201520162017201820192020202120222023202432033404346344337312815121067351
Scholar articles
R Sailer, T Jaeger, E Valdez, R Caceres, R Perez… - 21st Annual Computer Security Applications …, 2005
R Sailer, T Jaeger, E Valdez, R Caceres, R Perez… - Computer Security Applications Conference, 21st …, 2005