Shamon: A System for Distributed Mandatory Access Control

Source: Pennsylvania State University

Favorite

Free registration required

The authors define and demonstrate an approach to securing distributed computation based on a shared reference monitor(Shamon) that enforces Mandatory Access Control (MAC) policies across a distributed set of machines. The Shamon enables local reference monitor guarantees to be attained for a set of reference monitors on these machines. They implement a prototype system on the Xen hypervisor with a trusted MAC virtual machine built on Linux 2.6 whose reference monitor design requires only 13 authorization checks, only 5 of which apply to normal processing (others are for policy setup). They show that, through their architecture, distributed computations can be protected and controlled coherently across all the machines involved in the computation.
Format:PDF Size:180.10
Date:Sep 2006