DocumentCode
3003980
Title
A high-assurance, virtual guard architecture
Author
Heckman, M.R. ; Schell, R.R. ; Reed, E.E.
Author_Institution
Aesec Global Services, Palo Alto, CA, USA
fYear
2012
fDate
Oct. 29 2012-Nov. 1 2012
Firstpage
1
Lastpage
9
Abstract
Although one senior security professional has emphasized that “it is unconscionable to use overly weak components” in a multilevel security (MLS) context, the majority of current transfer guards do exactly that. Basic guard technology is well-developed and has a long history, but most guards are built on low-assurance systems vulnerable to software subversion, and the lack of assurance limits the range of transfers. This paper describes a virtual guard architecture that leverages mature MLS technology previously certified and deployed across domains from TS/SCI to Unclassified. The architecture permits a single guard system to simultaneously and securely support many different transfer functions between many different domain pairs. Not only does this architecture substantially address software subversion, support adaptable information transfer policies, and have the potential to dramatically reduce (re)certification effort, the virtualized guard execution environment also promises to significantly enhance efficient and scalable use of resources.
Keywords
security of data; TS/SCI; high-assurance virtual guard architecture; information transfer policies; multilevel security; software subversion; transfer functions; Computer architecture; Hardware; Kernel; Pipelines; Security; Assured pipeline; Downgrading; GEMSOS; Guard; High-assurance; Multilevel security; Sanitization; Virtualization;
fLanguage
English
Publisher
ieee
Conference_Titel
MILITARY COMMUNICATIONS CONFERENCE, 2012 - MILCOM 2012
Conference_Location
Orlando, FL
ISSN
2155-7578
Print_ISBN
978-1-4673-1729-0
Type
conf
DOI
10.1109/MILCOM.2012.6415677
Filename
6415677
Link To Document