Chinese wall isolation mechanism and its implementation on VMM

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

3 Scopus citations

Abstract

Virtualization is achieving increasing popularity and there are some mandatory access control (MAC) mechanisms available which control overt communications among virtual machines (VM) in virtual machine systems. However such mechanisms cannot block covert channels. A strong isolation mechanism at hardware layer can benefit solutions to this problem. Hence, in this paper we propose an isolation mechanism based on Chinese Wall policy to make an air-gap among VMs which have conflict of interest, and implement it on a popular virtual machine monitor (VMM), Xen. It regulates the VMM allocating hardware resources like physical memory, CPUs and I/O adapters to VMs without many losses of system performance. Hence it provides stronger isolation among VMs than VMMs do.

Original languageEnglish
Title of host publicationSystems and Virtualization Management
Subtitle of host publicationStandards and the Cloud -Third International DMTF Academic AllianceWorkshop, SVM 2009, Revised Selected Papers
EditorsLatifa Boursas, Mark Carlson, Hai Jin, Michelle Sibilla, KesWold
Pages13-18
Number of pages6
DOIs
StatePublished - 2010
Externally publishedYes
Event3rd International DMTF Academic Alliance Workshop on Systems and Virtualization Management: Standards and the Cloud, SVM 2009 - Wuhan, China
Duration: 22 Sep 200923 Sep 2009

Publication series

NameCommunications in Computer and Information Science
Volume71
ISSN (Print)1865-0929

Conference

Conference3rd International DMTF Academic Alliance Workshop on Systems and Virtualization Management: Standards and the Cloud, SVM 2009
Country/TerritoryChina
CityWuhan
Period22/09/0923/09/09

Fingerprint

Dive into the research topics of 'Chinese wall isolation mechanism and its implementation on VMM'. Together they form a unique fingerprint.

Cite this