DocumentCode
2595103
Title
Seamless virtual machine live migration on network security enhanced hypervisor
Author
Xianqin, Chen ; Han, Wan ; Sumei, Wang ; Xiang, Long
Author_Institution
State Key Lab. of Virtual Reality Technol. & Syst., Beijing Univ. of Aeronaut. & Astronaut., Beijing, China
fYear
2009
fDate
18-20 Oct. 2009
Firstpage
847
Lastpage
853
Abstract
Since the virtual network traffic is invisible outside the hypervisor, it is impossible for traditional network-base security devices to harness the attacks happened in virtual computing environment. Industry and academies adopt the network security enabled hypervisor (NSE-H) to protect virtual machines (VM) residing in the virtual network. In this paper, we identified the insufficiency of the existing live migration implementation, which prevents itself from providing transparent VM relocation between NSE-Hs. This occurs because the contemporary migration implementation only takes VM encapsulated states into account, but ignores VM related security context(SC) needed by NSE-H embedded security engines (SE). We presented a comprehensive live migration framework for the NSE-H, considering both the execution context encapsulated in VM instance and the VM related security context within the SEs. We built a prototype system of the framework based on stateful firewall enabled Xen hypervisor. Our experiment was performed with realistic applications and the results demonstrate that the solution complements the insufficiency without introducing significant performance downgrade. Even in the worst case, the downtime that occurs during migration increases no more than 15%, comparing to existing implementation.
Keywords
authorisation; computer networks; operating systems (computers); virtual machines; NSE-H; SE; VM execution context encapsulation; contemporary migration framework; efficiency 15 percent; embedded security engine; multiple operating system; network security enhanced hypervisor; network-base security device; prototype system; stateful firewall enabled Xen hypervisor; system virtualization technology; transparent VM relocation; virtual computing environment; virtual machine live migration; Computer networks; Engines; Hardware; Platform virtualization; Protection; Resource virtualization; Space technology; Virtual machine monitors; Virtual machining; Virtual manufacturing; hypervisor; live migration; network security; virtualization;
fLanguage
English
Publisher
ieee
Conference_Titel
Broadband Network & Multimedia Technology, 2009. IC-BNMT '09. 2nd IEEE International Conference on
Conference_Location
Beijing
Print_ISBN
978-1-4244-4590-5
Electronic_ISBN
978-1-4244-4591-2
Type
conf
DOI
10.1109/ICBNMT.2009.5347800
Filename
5347800
Link To Document