西安交通大学电子与信息工程学院,西安,710049
网络首发:2013-10-10,
纸质出版:2013
移动端阅览
郑豪 1, 张兴军 1, 王恩东 2, 等. 一种采用驱动隔离的宿主机可靠性方法[J]. 西安交通大学学报, 2013,47(10):7-12+26.
Improving the Reliability of Host Machine with Driver Isolation[J]. 2013, 47(10): 7-12+26.
郑豪 1, 张兴军 1, 王恩东 2, 等. 一种采用驱动隔离的宿主机可靠性方法[J]. 西安交通大学学报, 2013,47(10):7-12+26. DOI: 10.7652/xjtuxb201310002.
Improving the Reliability of Host Machine with Driver Isolation[J]. 2013, 47(10): 7-12+26. DOI: 10.7652/xjtuxb201310002.
针对虚拟化环境下宿主机中的驱动程序故障容易造成宿主机及其虚拟机崩溃的问题
提出了一种采用驱动隔离的宿主机可靠性方法。该方法基于StyleBox架构的保护域功能
将其扩展用于复杂接口的驱动程序的隔离
包括:为驱动和内核的复杂交互接口建立包装函数
从而限定驱动程序运行在保护域中; 为驱动程序提供私有内存
以保证驱动程序能够在保护域内正常运行。实验结果表明:在利用该方法修改的Linux2.6.28.10宿主机内核中
对于随机注入网卡驱动并造成内核破坏的错误
该方法可以有效检测90.63%的注入错误
并成功隔离67.5%的注入错误
防止了驱动故障传播到宿主机内核
提高了宿主机的可靠性。
An approach to improve the reliability of the host machines with driver isolation is proposed to solve the problem that the driver fault crashes the host machines and its virtual machines. The approach is based on the protection domain of the pre-developed architecture StyleBox and extends it to isolate the driver with complex interfaces. For detail
it creates wrapper functions for the complex interactive interfaces between the driver and the kernel
limits the driver running in the protection domain
and provides private memories for isolated drivers to support the driver's normal operation in the protection domain. Experimental results on a Linux2.6.28.10 host machine kernel that is modified using the proposed approach show that the approach successfully detects 90.63% of the faults
which are randomly injected to the network driver and damage the host machines kernel
and isolates 67.5% of them
and that the reliability of host machines is improved.
SWIFT M M, BERSHAD B N, LEVY H M. Improving the reliability of commodity operating systems [J]. ACM Transactions on Computer Systems, 2005, 23(1): 77-110.
LEVASSEUR J, UHLIG V, STOESS J, et al. Unmodified device driver reuse and improved system dependability via virtual machines [C]∥Proceedings of the 6th USENIX Symposium on Operating Systems Design and Implementation. Berkeley, CA, USA: USENIX, 2004: 17-30.
TAN L, CHAN E M, FARIVAR R, et al. iKernel: isolating buggy and malicious device drivers using hardware virtualization support [C]∥Proceedings of the Third IEEE International Symposium on Dependable, Autonomic and Secure Computing. Piscataway, NJ, USA: IEEE, 2007: 134-144.
GANAPATHY V, RENZELMANN M J, BALAKRISHNAN A, et al. The design and implementation of microdrivers [J]. ACM SIGOPS Operating Systems Review, 2008, 42(2): 168-178.
WILLIANS D, REYNOLDS P, WALSH K, et al. Device driver safety through a reference validation mechanism [C]∥Proceedings of the 8th USENIX Symposium on Operating Systems Design and Implementation. Berkeley, CA, USA: USENIX, 2008: 241-254.
华保健, 陈意云, 李兆鹏, 等. 安全语言PointerC的设计及形式证明 [J]. 计算机学报, 2008, 31(4): 556-564.
HUA Baojian, CHEN Yiyun, LI Zhaopeng, et al. Design and proof of a safe programming language PointerC [J]. Chinese Journal of Computers, 2008, 31(4): 556-564.
ZHOU F, CONDIT J, ANDERSON Z, et al. SafeDrive: safe and recoverable extensions using language-based techniques [C]∥Proceedings of the 7th USENIX Symposium on Operating Systems Design and Implementation. Berkeley, CA, USA: USENIX, 2006: 45-60.
CASTRO M, COSTA M, MARTIN J, et al. Fast byte-granularity software fault isolation [C]∥Proceedings of the ACM SIGOPS 22nd Symposium on Operating Systems Principles. New York, USA: ACM, 2009: 45-58.
ZHENG Hao, ZHANG Xinjun, WANG Endong, et al. Achieving High Reliability on Linux for K2 System [C]∥Proceedings of the 2012 IEEE/ACIS 11th International Conference on Computer and Information Science. Piscataway, NJ, USA: IEEE, 2012: 107-112.
0
浏览量
4
下载量
0
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621