Multipersona Hypovisors: Securing Mobile Devices through High-Performance Light-Weight Subsystem Isolation
Author
Krishnan, Neelima
Hitefield, Seth
Clancy, T. Charles
McGwier, Robert W.
Tront, Joseph G.
Date
2013-06-28Metadata
Show full item recordAbstract
We propose and detail a system called multipersona Hypovisors for providing light-weight isolation for enhancing security on Multipersona mobile devices, particularly with respect to the current memory constraints of these devices.
Multipersona Hypovisors leverage Linux kernel cGroups and namespaces to establish independent process container, al-lowing isolation of the Multipersona process tree from other simultaneous instances of Multipersona and the hypovisor which is an underlying Angstrom-based embedded Linux distributions designed to add additional security to the system. The system incorporates a wide range of data integrity tools in the embedded hypovisor, and an SE Linux-enabled kernel for mandatory access control and integrity tools for transparent auditing of running Multipersona instances.
A prototype is presented which uses integrity tools external to the Multipersona container to audit it for malicious activity, and also has the ability to support a multipersona environment with multiple encrypted personas existing individually or simultaneously on the device. Two versions are demonstrated, one which allows cold-swapping of personas for high-assurance scenarios and also one that supports hot-swapping.
Analysis shows that the hypovisor has a 40-50 MB impact on the overall memory footprint for the system.
Description
Funded by Naval Postgraduate School
Rights
This publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States.Collections
Related items
Showing items related by title, author, creator and subject.
-
Active Control of Adaptive Optics System in a Large Segmented Mirror Telescope
Nagashima, M.; Agrawal, B.N. (2012);For a large Adaptive Optics (AO) system such as a large Segmented Mirror Telescope (SMT), it is often difficult, although not impossible, to directly apply common Multi-Input Multi-Output (MIMO) controller design methods ... -
Spin stabilization of the ORION satellite using a thruster attitude control system with optimal control considerations
Cunningham, Janet L. (Naval Postgraduate School, 1989);The controlled system is the ORION satellite spinning about its single axis of symmetry. Hydrazine thrusters are used as the control and are modeled by ideal, constant magnitude step functions. The system is normalized and ... -
Acquisition and Development Programs through the Lens of System Complexity
Pugliese, Antonio; Enos, James; Nilchiani, Roshanak (Monterey, California. Naval Postgraduate School, 2018-04-30); SYM-AM-18-165The approach of the Department of Defense (DoD) to acquisition programs is strongly based on systems engineering. DoD Directive 5000.01 calls for "the application of a systems engineering approach that optimizes total ...