In today’s society, people face a plenty of software systems problems and communications security issues when using computer. Because the harm of the viruses and torjans, and some websites spread bad information, steal personal privacy, as well as viruses that removable media carries, make people pay a lot of attention on that.Operating system security mechanisms are the basic of the computer security, provide an effective security mechanism to application software in application layer, to.solve the problem that computer faces.But, Most of computer systems or application models are mounted directly on top of the machine, use the operating system’s security mechanism to protect. And when the operating system’s security mechanism have broken, such as viruses or torjans have already acquired system control authority, they can get critical data from internal, that way threat the communicate of operating system.Transfer the operating system that directly mounted on the machine to the virtualization platform, and use the security measures of the Host operating system to protect Guest operating system. make the Host operating system controls the key hardware, make the operating system’s security policy deployed outside. With the help of the virtualization,research and design IP address-based packet filtering,interface name-based packet filtering and port number-based packet filtering; Then adding encryption algorithms in the device driver, make the encryption process does not interfere by the application, get higher protection of the critical data.In this paper, uses a combination of theory and practice research way, demonstrated operating system communication security mechanism that based on virtualization and device driver technology. The mechanism in line with the objectives established at the beginning of the title, and there have rooms for expansion and improvement. |