TY - GEN
T1 - Building a security OS with software defined infrastructure
AU - Gu, Guofei
AU - Hu, Hongxin
AU - Keller, Eric
AU - Lin, Zhiqiang
AU - Porter, Donald E.
N1 - Publisher Copyright: © 2017 ACM.
PY - 2017/9/2
Y1 - 2017/9/2
N2 - The recent emergence of Software-Defined Infrastructure (SDI) offers a number of useful tools for managing, monitoring, containing, shepherding, and recovering computing units within an enterprise, cloud, or data center. As SDI utilities grow and the types of resources that can be abstracted into software-managed control and data planes increase, there is a pressing need for datacenter-level operating systems (OSes). Such a datacenter-level OS can further abstract and easily capture higher-level policy goals, and push them down to different types of hardware and software, ranging from application processes to storage and networking. This paper thus proposes S2OS, an SDI-defined Security OS, which offers an easy-to-use, programmable security model for monitoring and dynamically securing applications. We anticipate S2OS could unlock a wide range of unprecedented security opportunities, including fine-grained and dynamic security programmability at infrastructure scale, and information flow tracking across an entire infrastructure.
AB - The recent emergence of Software-Defined Infrastructure (SDI) offers a number of useful tools for managing, monitoring, containing, shepherding, and recovering computing units within an enterprise, cloud, or data center. As SDI utilities grow and the types of resources that can be abstracted into software-managed control and data planes increase, there is a pressing need for datacenter-level operating systems (OSes). Such a datacenter-level OS can further abstract and easily capture higher-level policy goals, and push them down to different types of hardware and software, ranging from application processes to storage and networking. This paper thus proposes S2OS, an SDI-defined Security OS, which offers an easy-to-use, programmable security model for monitoring and dynamically securing applications. We anticipate S2OS could unlock a wide range of unprecedented security opportunities, including fine-grained and dynamic security programmability at infrastructure scale, and information flow tracking across an entire infrastructure.
KW - Security operating system
KW - Software-defined infrastructure
UR - https://www.scopus.com/pages/publications/85030549059
U2 - 10.1145/3124680.3124720
DO - 10.1145/3124680.3124720
M3 - Conference contribution
T3 - Proceedings of the 8th Asia-Pacific Workshop on Systems, APSys 2017
BT - Proceedings of the 8th Asia-Pacific Workshop on Systems, APSys 2017
PB - Association for Computing Machinery, Inc
T2 - 8th ACM Asia Pacific Conference on Systems, APSys 2017
Y2 - 2 September 2017
ER -