Authors
Jonathan M McCune, Stefan Berger, Ramon Caceres, Trent Jaeger, Reiner Sailer
Publication date
2005/11
Journal
IBM Res. Div., Res. Rep. RC23778
Description
We define and demonstrate an approach to securing distributed computation based on a distributed reference monitor that enforces mandatory access control (MAC) policy across machines. Securing distributed computation is difficult because of the asymmetry of trust in different computing environments and the complexity of managing MAC policies across machines, when they are already complex for one machine (eg, Fedora Core 4 SELinux policy). We leverage recent work in three areas as a basis for our solution:(1) remote attestation as a basis to establish mutual acceptance of reference monitoring function;(2) IPsec with MAC labels to ensure the protection and authorization of commands across machines; and (3) virtual machines for isolation and to simplify the MAC policies. We define a distributed computing architecture based on these mechanisms and show how local reference monitor guarantees can be …
Total citations
2005200620072008200920102011201220132014121
Scholar articles
JM McCune, S Berger, R Caceres, T Jaeger, R Sailer - IBM Res. Div., Res. Rep. RC23778, 2005