• DocumentCode
    2595103
  • Title

    Seamless virtual machine live migration on network security enhanced hypervisor

  • Author

    Xianqin, Chen ; Han, Wan ; Sumei, Wang ; Xiang, Long

  • Author_Institution
    State Key Lab. of Virtual Reality Technol. & Syst., Beijing Univ. of Aeronaut. & Astronaut., Beijing, China
  • fYear
    2009
  • fDate
    18-20 Oct. 2009
  • Firstpage
    847
  • Lastpage
    853
  • Abstract
    Since the virtual network traffic is invisible outside the hypervisor, it is impossible for traditional network-base security devices to harness the attacks happened in virtual computing environment. Industry and academies adopt the network security enabled hypervisor (NSE-H) to protect virtual machines (VM) residing in the virtual network. In this paper, we identified the insufficiency of the existing live migration implementation, which prevents itself from providing transparent VM relocation between NSE-Hs. This occurs because the contemporary migration implementation only takes VM encapsulated states into account, but ignores VM related security context(SC) needed by NSE-H embedded security engines (SE). We presented a comprehensive live migration framework for the NSE-H, considering both the execution context encapsulated in VM instance and the VM related security context within the SEs. We built a prototype system of the framework based on stateful firewall enabled Xen hypervisor. Our experiment was performed with realistic applications and the results demonstrate that the solution complements the insufficiency without introducing significant performance downgrade. Even in the worst case, the downtime that occurs during migration increases no more than 15%, comparing to existing implementation.
  • Keywords
    authorisation; computer networks; operating systems (computers); virtual machines; NSE-H; SE; VM execution context encapsulation; contemporary migration framework; efficiency 15 percent; embedded security engine; multiple operating system; network security enhanced hypervisor; network-base security device; prototype system; stateful firewall enabled Xen hypervisor; system virtualization technology; transparent VM relocation; virtual computing environment; virtual machine live migration; Computer networks; Engines; Hardware; Platform virtualization; Protection; Resource virtualization; Space technology; Virtual machine monitors; Virtual machining; Virtual manufacturing; hypervisor; live migration; network security; virtualization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Broadband Network & Multimedia Technology, 2009. IC-BNMT '09. 2nd IEEE International Conference on
  • Conference_Location
    Beijing
  • Print_ISBN
    978-1-4244-4590-5
  • Electronic_ISBN
    978-1-4244-4591-2
  • Type

    conf

  • DOI
    10.1109/ICBNMT.2009.5347800
  • Filename
    5347800