A mandatory access control framework in virtual machine system with respect to multilevel security II: Implementation

  • Liu Qian*
  • , Wang Guanhai
  • , Weng Chuliang
  • , Luo Yuan
  • , Li Minglu
  • *Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

5 Scopus citations

Abstract

This paper is a continuation of our last paper [1] which describes the theory of Virt-BLP model. Based on Virt-BLP model, this paper implements a mandatory access control (MAC) framework applicable to multi-level security (MLS) in Xen. The Virt-BLP model is the theoretical basis of this MAC framework, and this MAC framework is the implementation of Virt-BLP model. Our last paper focuses on Virt-BLP model, while this paper concentrates on the design and implementation of MAC framework. For there is no MAC framework applicable to MLS in virtual machine system at present, our MAC framework fills the blank by applying Virt-BLP model to Xen, which is better than current researches to guarantee the security of communication between virtual machines (VMs). The experimental results show that our MAC framework is effective to manage the communication between VMs.

Original languageEnglish
Pages (from-to)86-94
Number of pages9
JournalChina Communications
Volume8
Issue number2
StatePublished - Mar 2011
Externally publishedYes

Keywords

  • MAC framework
  • Multi-level security
  • Virt-BLP model
  • Xen

Fingerprint

Dive into the research topics of 'A mandatory access control framework in virtual machine system with respect to multilevel security II: Implementation'. Together they form a unique fingerprint.

Cite this