DocumentCode :
2595103
Title :
Seamless virtual machine live migration on network security enhanced hypervisor
Author :
Xianqin, Chen ; Han, Wan ; Sumei, Wang ; Xiang, Long
Author_Institution :
State Key Lab. of Virtual Reality Technol. & Syst., Beijing Univ. of Aeronaut. & Astronaut., Beijing, China
fYear :
2009
fDate :
18-20 Oct. 2009
Firstpage :
847
Lastpage :
853
Abstract :
Since the virtual network traffic is invisible outside the hypervisor, it is impossible for traditional network-base security devices to harness the attacks happened in virtual computing environment. Industry and academies adopt the network security enabled hypervisor (NSE-H) to protect virtual machines (VM) residing in the virtual network. In this paper, we identified the insufficiency of the existing live migration implementation, which prevents itself from providing transparent VM relocation between NSE-Hs. This occurs because the contemporary migration implementation only takes VM encapsulated states into account, but ignores VM related security context(SC) needed by NSE-H embedded security engines (SE). We presented a comprehensive live migration framework for the NSE-H, considering both the execution context encapsulated in VM instance and the VM related security context within the SEs. We built a prototype system of the framework based on stateful firewall enabled Xen hypervisor. Our experiment was performed with realistic applications and the results demonstrate that the solution complements the insufficiency without introducing significant performance downgrade. Even in the worst case, the downtime that occurs during migration increases no more than 15%, comparing to existing implementation.
Keywords :
authorisation; computer networks; operating systems (computers); virtual machines; NSE-H; SE; VM execution context encapsulation; contemporary migration framework; efficiency 15 percent; embedded security engine; multiple operating system; network security enhanced hypervisor; network-base security device; prototype system; stateful firewall enabled Xen hypervisor; system virtualization technology; transparent VM relocation; virtual computing environment; virtual machine live migration; Computer networks; Engines; Hardware; Platform virtualization; Protection; Resource virtualization; Space technology; Virtual machine monitors; Virtual machining; Virtual manufacturing; hypervisor; live migration; network security; virtualization;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Broadband Network & Multimedia Technology, 2009. IC-BNMT '09. 2nd IEEE International Conference on
Conference_Location :
Beijing
Print_ISBN :
978-1-4244-4590-5
Electronic_ISBN :
978-1-4244-4591-2
Type :
conf
DOI :
10.1109/ICBNMT.2009.5347800
Filename :
5347800
Link To Document :
بازگشت