查看: 1869|回复: 3
收起左侧

[分享] 基于Xen的安全操作系统 - Qubes 1.0 rc1

[复制链接]
ghfujianbin
发表于 2012-7-31 11:00:37 | 显示全部楼层 |阅读模式
本帖最后由 ghfujianbin 于 2012-7-31 11:08 编辑

大体介绍:
Qubes implements Security by Isolation approach. To do this, Qubes utilizes virtualization technology, to be able to isolate various programs from each other, and even sandbox many system-level components, like networking or storage subsystem, so that their compromise don’t affect the integrity of the rest of the system.

Qubes lets the user define many security domains implemented as lightweight Virtual Machines (VMs), or “AppVMs”. E.g. user can have “personal”, “work”, “shopping”, “bank”, and “random” AppVMs and can use the applications from within those VMs just like if they were executing on the local machine, but at the same time they are well isolated from each other. Qubes supports secure copy-and-paste and file sharing between the AppVMs, of course.








主要特点:
  • Based on a secure bare-metal hypervisor (Xen)
  • Networking code sand-boxed in an unprivileged VM (using IOMMU/VT-d)
  • No networking code in the privileged domain (dom0)
  • All user applications run in “AppVMs”, lightweight VMs based on Linux
  • Centralized updates of all AppVMs based on the same template
  • Qubes GUI virtualization presents applications like if they were running locally
  • Qubes GUI provides isolation between apps sharing the same desktop
  • Storage drivers and backends sand-boxed in an unprivileged virtual machine(*)
  • Secure system boot based on Intel TXT(*)

(*) Indicates feature that is planned for future releases, currently not implemented.

官网:http://qubes-os.org/Home.html

Qubes的最大优点就是安全。它充分利用了虚拟化技术(基于安全虚拟机Xen),所有用户应用程序都运行在AppVM(基于Linux的轻量级虚 拟机)中,彼此隔离。而联网代码使用IOMMU/VT-d放在一个非特权虚拟机中,在特权域 (dom0) 中没有任何联网代码。许多系统级组件放在沙盒中,以避免互相影响。


具体中文介绍参考cnbeta:http://www.cnbeta.com/articles/108318.htm

开发者 - 波兰著名女黑客 - Joanna Rutkowska



qq5150
发表于 2012-8-1 22:26:10 | 显示全部楼层
下载是个问题 楼主有分流么?
ghfujianbin
 楼主| 发表于 2012-8-1 23:33:52 | 显示全部楼层
qq5150 发表于 2012-8-1 22:26
下载是个问题 楼主有分流么?

没有分流呢 我也是看下载速度太慢 懒得下载了...
qq5150
发表于 2012-8-1 23:53:26 | 显示全部楼层
ghfujianbin 发表于 2012-8-1 23:33
没有分流呢 我也是看下载速度太慢 懒得下载了...

我这下也很慢 懒得下了
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-24 07:04 , Processed in 0.132210 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表