Opening book details…
Can I read Virtual Ghost: Protecting Applications from Hostile Operating Systems on EtoBox?
Virtual Ghost: Protecting Applications from Hostile Operating Systems by John Criswell; Nathan Dautenhahn; Vikram Adve is a scholarly article available to read on EtoBox.
What is Virtual Ghost: Protecting Applications from Hostile Operating Systems about?
Applications that process sensitive data can be carefully designed and validated to be difficult to attack, but they are usually run on monolithic, commodity operating systems, which may be less secure. An OS compromise gives the attacker complete access to all of an application's data, regardless of how well the application is built. We propose a new system, Virtual Ghost, that protects applications from a compromised or even hostile OS. Virtual Ghost is the first system to do so by combining compiler instrumentation and run-time checks on operating system code, which it uses to create ghost memory that the operating system cannot read or write. Virtual Ghost interposes a thin hardware abstraction layer between the kernel and the hardware that provides a set of operations that the kernel must use to manipulate hardware, and provides a few trusted services for secure applications such as ghost memory management, encryption and signing services, and key management. Unlike previous solutions, Virtual Ghost does not use a higher privilege level than the kernel. Virtual Ghost performs well compared to previous approaches; it outperforms InkTag on five out of seven of the LMBench microb
- Author
- John Criswell; Nathan Dautenhahn; Vikram Adve
- Publisher
- ACM
- Published
- 2014
- Language
- EN
More by John Criswell; Nathan Dautenhahn; Vikram Adve
Browse all works by John Criswell; Nathan Dautenhahn; Vikram Adve