Outline for March 12, 2007
-
Greetings and Felicitations!
-
Confinement problem
-
What it is
-
Covert channels
-
Rule of transitive confinement
-
Difficulty of preventing leaking
-
Isolation: virtual machines
-
What it is
-
Example: KVM/370
-
Example: VAX/VMM
-
Isolation: sandboxes
-
What it is
-
Adding mechanisms to libraries or kernel
-
Modify program or process to be executed
-
Example: Janus
-
Covert channels
-
Storage vs. timing
-
Noise vs. noiseless
-
Existence
-
Bandwidth
Here is a PDF version of this document.