节点文献

不可信系统平台下的敏感信息管理系统

Sensitive information management system for un-trusted system platforms

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 谢学智王瑀屏谈鉴锋陈启庚

【Author】 XIE Xuezhi;WANG Yuping;TAN Jianfeng;CHEN Qigeng;Department of Computer Science and Technology,Tsinghua University;

【机构】 清华大学计算机科学与技术系

【摘要】 通用操作系统存在大量后门和漏洞等安全威胁,使得应用程序中处理的敏感信息的机密性难以得到完备的保护。该文设计并实现了敏感内存管理(sensitive memory manager,SMM)系统,在应用程序配合下对存放敏感信息的内存进行保护,阻止攻击者利用系统内核窃取敏感信息的企图。该系统基于虚拟化技术,通过为被保护进程的用户态和内核态设置不同影子页表的方式,使得应用程序能够访问的敏感信息不会被操作系统内核访问。有效性评测和性能评测表明:该系统提供的内存保护粒度更小,带来的性能损耗更小。

【Abstract】 The threats of backdoors and vulnerabilities in general-purpose operating systems complicate protection of sensitive information.This paper describes a sensitive memory management system(SMM)which protects sensitive information memory and prevents attackers from obtaining sensitive information by compromising the operating system kernel.Virtualization is used to set up different shadow page tables for the user-mode and the kernel-mode of the protected process and then controls access to the sensitive information so that only the proper applications can access the information and not the operating systems kernel.Tests show that the memory is protected with finer granularity and lower overhead than previous methods.

【基金】 北京高等学校青年英才计划项目(YETP0108)
  • 【文献出处】 清华大学学报(自然科学版) ,Journal of Tsinghua University(Science and Technology) , 编辑部邮箱 ,2015年11期
  • 【分类号】TP309;TP315
  • 【被引频次】1
  • 【下载频次】125
节点文献中: 

本文链接的文献网络图示:

本文的引文网络