Dissertation > Excellent graduate degree dissertation topics show
Research and Implementation of BLP Based Network Access Control Mechanism on Virtualization Platform
Author: LiuSuNa
Tutor: PanLi
School: Shanghai Jiaotong University
Course: Communication and Information System
Keywords: Network Access Control Virtualization BLP model Reference monitor XEN
CLC: TP393.08
Type: Master's thesis
Year: 2011
Downloads: 26
Quote: 0
Read: Download Dissertation
Abstract
|
With the development of the Internet, especially the rise of cloud computing, distributed systems, applications, network data security have become increasingly demanding, at the same time, as one of the key technologies to build a cloud computing infrastructure virtualization to provide a more open, more interactive web environment. The traditional access control technologies such as firewalls, it is difficult to prevent active leakage and malicious Trojan attacks, can not meet the security requirements under the virtualization platform. Therefore, how to ensure that both can be fully shared network resources in virtualized environments, but also to achieve the strict access control to become the current problems to be solved. Higher security requirements of the system, such as government departments or bank document management system, the more resources in the form of different security classification divided the entire system with strict mandatory access policy to protect data confidentiality and integrity. BLP model is the first to be able to provide data confidentiality protection of sub-level security policy model, it is based on the information flow policy, by allowing one-way flow of information from the low security level to a high level of security systems, to achieve multi-level access control; Meanwhile, BLP model is the first complete formal methods of system security, strict proof of a mathematical model. Because of its versatility and theoretical security system with high security needs, BLP model has been widely studied and applied. Firstly extended BLP model of stand-alone systems, from basic network elements and communication mechanisms, and propose a more general and fine-grained access control models - N-BLP model theoretically and verify the safety of the model sex. Compared to the other network access control model, N-BLP model is completely in line with the traditional the BLP model security axiom connection establishment and transmission of data streams at the same time be able to fine-grained control to ensure the secure transmission of the information flow between the different security classification entity network . Then to Xen virtual machine as a research reference environment, the N-BLP model applied to virtual technology environment, at the same time considering the more than physical machines, virtual machines alliance between the access control and same physical machine on a different client machine via shared memory access control proposed access control mechanism in a more complete set of virtualized environments. Access control between virtual machines Union, the paper proposes a D-BLP model for the exchange of information between the Control Union. The proposed access control mechanism to fully take into account the various resource sharing in virtualized environments, and fine-grained control, suitable for applications in e-government, data centers and other large-scale distributed network system. On this basis, the paper gives the framework of the implementation of network access control mechanism in the virtualization platform, including UEFI-based policy configuration, Net-Filter-based host-guest security label passed, based on the the LSM application layer data checks based XSM shared memory access control.
|
Related Dissertations
- Management and Collaboration of Applications in Virtual Desktop System,TP316.7
- Research on Sound Device Virtualization in Xen,TP391.9
- The virtual machine image file space waste recovery system,TP302
- Based on logical hierarchical storage system design and implementation,TP333
- Xen virtualization network I / O optimization method,TP302
- Hardware-based counters virtualization performance evaluation of multiple virtual machines,TP302
- Virtual environment multiple network interface card I / O Scheduling System,TP334.7
- Lightweight Virtual Machine Manager and Security Applications,TP302
- Lock-based multiprocessor -aware scheduling system VCPU,TP332
- Lightweight , multi-platform virtual machine extension,TP391.9
- CPU overhead virtual computing environment measurement system,TP332
- Virtual desktop environment data to redundant system design and implementation,TP333
- Virtual domain access control system protection mechanisms,TP309.2
- For the mobile platform desktop virtualization mechanism,TP316.7
- Block-level continuous data protection for virtual recovery technology,TP309
- Logically oriented virtual domain multi -level access control system,TP309
- Template- based virtual machine memory cloud computing services system,TP393.09
- File Protection System Research Based on Hardware Assisted Virtualization,TP309
- VM-based security monitoring studies,TP274
- Virtual desktop and application management research,TP316.7
- Linux-based distributed switch device virtualization technology research,TP393.05
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|