Presentation is loading. Please wait.

Presentation is loading. Please wait.

CS 6501- Overshadow Response Michael Deighan (9/1/09) ● Goals  application authenticity  execution integrity  data privacy ● Options  Overshadow extension.

Similar presentations


Presentation on theme: "CS 6501- Overshadow Response Michael Deighan (9/1/09) ● Goals  application authenticity  execution integrity  data privacy ● Options  Overshadow extension."— Presentation transcript:

1 CS 6501- Overshadow Response Michael Deighan (9/1/09) ● Goals  application authenticity  execution integrity  data privacy ● Options  Overshadow extension  CHAOS  LOKI  INVISIOS

2 Overshadow Extension Towards Application Security on Untrusted Operating Systems Dan R. K. Ports and Tal Garfinkel Use shim to protect: ● file system ● inter-process communications ● process management ● time and randomness ● I/O and trusted paths ● identity management ● error handling http://www.usenix.org/events/hotsec08/tech/full_papers/ports/ports.pdf

3 CHAOS Tamper-Resistant Execution in an Untrusted Operating System Using a Virtual Machine Monitor Haibo Chen, Fengzhe Zhang, Cheng Chen, Ziye Yang, Rong Chen, Binyu Zang http://ppi.fudan.edu.cn/system/publications/paper/chaos-ppi-tr.pdf

4 LOKI Hardware Enforcement of Application Security Policies Using Tagged Memory Nickolai Zeldovich, Hari Kannan, Michael Dalton, and Christos Kozyrakis http://www.usenix.org/events/osdi08/tech/full_papers/zeldovich/zeldovich_html/

5 INVISIOS INVISIOS: A Lightweight, Minimally Intrusive Secure Execution Environment Divya Arora, Najwa Aaraj, Anand Raghunathan, Niraj K. Jha http://www.princeton.edu/~jha/files/CE-J09-001.pdf

6 Discussion ● What are the pros and cons of each option? ● How will each affect application development? ● Which option deserves further investigation?


Download ppt "CS 6501- Overshadow Response Michael Deighan (9/1/09) ● Goals  application authenticity  execution integrity  data privacy ● Options  Overshadow extension."

Similar presentations


Ads by Google