Skip to main content

Find us on

facebook youtube flickr

Upcoming Events

faculty guide

My Computer Ate My Data, Changed My Students' Grades and Stole My Money
OR
What all faculty need to know about securing their information
February 3, 2012

Past Programs

bigham video

Real-Time Crowd Support for People with Disabilities
Jeff Bigham
University of Rochester
November 15, 2011 

cyberops vid

Cyber Operations and National Security
A Panel Discussion
October 20, 2011

summer camp vid

CISO vs. Adversary
Healthcare Security Investment Game
July 7, 2011 

troopers vid

Adventures in SCADA
TROOPERS 2011
April 30, 2011

 

Newsletter - Summer/Fall 2010

summerfall newsletter

Institute for Security, Technology, and Society
Dartmouth College
6211 Sudikoff Laboratory
Hanover, NH 03755 USA
info.ists@dartmouth.edu
HomeEvents >

Building Shared Reference Monitor Systems

Abstract

Trent JaegerIn this talk, I will describe an architecture for building secure distributed systems based on a Shared Reference Monitor (Shamon). A Shamon consists of distributed security components that collaborate to provide a single, coherent mechanism for enforcing mandatory access control (MAC), achieving the function of a local reference monitor.

The challenge is to ensure the guarantees required of a reference monitor: complete mediation over security sensitive operations; tamper-protection of the Shamon mechanism and state; and verifiability of correct enforcement of security goals. I will begin the talk by discussing the vision of future Shamon distributed systems and motivating why the recent emergence of ubiquitous virtual machine systems and trusted computing hardware is necessary to achieve the Shamon goals. I will then discuss our prototype Shamon system, highlighting the design decisions required to satisfy the reference monitor guarantees.

Bio

Trent Jaeger is an Associate Professor in the Computer Science and Engineering Department at The Pennsylvania State University. Trent's research interests include operating systems security, access control, and source code and policy analysis tools. He has published over 50 refereed research papers on these subjects. Trent has made a variety of contributions to Linux security, particularly to the Linux Security Modules framework, the SELinux module and policy development, integrity measurement in Linux, and the Xen security architecture.

Also, he has been a member of the program committee, including as general and program chair, for several major security conferences. Trent has an M.S. and a Ph.D. from the University of Michigan, Ann Arbor in Computer Science and Engineering in 1993 and 1997, respectively.