[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] trusted computing



Tim Freeman wrote:

not about Xen in particular, but as a side note, because I think some
people are interested in trusted computing and virtualization?  If
you're not, sorry for the intrusion!

http://www.research.ibm.com/secure_systems_department/projects/tcglinux/

"Currently, we experiment measuring the information flow on SELinux
systems to reason about isolation properties of a system. For this
purpose, we modified tcgLinux to run as an LSM kernel module stacked on
top of SELinux. We also envision to extend our attestation method to
integrate virtualization technology and partition the attestation space
of a system using the information flow policies enforced therein."

# [tcgLinux]'s main goal is to generate verifiable representative information
# about the software stack running on a Linux system. This information can
# be used by remote parties to determine the integrity of the execution
# environment.

Can it, though? The assumption seems to be that fingerprinting executables
is sufficient to characterise the security configuration of a system.
AFAICS that's patently false: the security of a system is dependent on its
complete configuration, including many non-executable files. IOW, anyone
can compromise a system without changing any executable files.

# We instrumented the Linux kernel to trigger a measurement for each
# executable, library, or kernel module loaded into the run-time before
# they affect the system.

Yep, only executables. This seems quite useless.

--
David Hopwood <david.nospam.hopwood@xxxxxxxxxxxxxxxx>



-------------------------------------------------------
This SF.net email is sponsored by: IT Product Guide on ITManagersJournal
Use IT products in your business? Tell us what you think of them. Give us
Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more
http://productguide.itmanagersjournal.com/guidepromo.tmpl
_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxxxx
https://lists.sourceforge.net/lists/listinfo/xen-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.