DocumentCode :
3508421
Title :
PALM: Security Preserving VM Live Migration for Systems with VMM-enforced Protection
Author :
Zhang, Fengzhe ; Huang, Yijian ; Wang, Huihong ; Chen, Haibo ; Zang, Binyu
Author_Institution :
Parallel Process. Inst., Fudan Univ., Shanghai
fYear :
2008
fDate :
14-17 Oct. 2008
Firstpage :
9
Lastpage :
18
Abstract :
Live migration of virtual machine (VM) is a desirable feature for distributed computing such as grid computing and recent cloud computing by facilitating fault tolerance, load balance, and hardware maintenance. Virtual machine monitor (VMM) enforced process protection is a newly advocated approach to provide a trustworthy execution environment for processes running on commodity operating systems.While VMM-enforced protection systems extend protection to the processes in the virtual machine (VM), it also breaks the mobility of VMs since a VM is more closely bound to the VMM. Furthermore, several security vulnerabilities exists in migration, especially live migration of such systems that may degrade the protection strength or even break the protection.In this paper, we propose a secure migration system that provides live migration capability to VMs in VMM-enforced process protection systems, while not degrading the protection level. We implemented a prototype system base on Xen and GNU Linux to evaluate the design. The results shows that no serious performance degradation is incurred comparing to Xen live migration system.
Keywords :
Linux; grid computing; security of data; virtual machines; GNU Linux; PALM; VMM-enforced protection; Xen; cloud computing; commodity operating systems; distributed computing; fault tolerance; grid computing; hardware maintenance; load balance; process protection; security preserving VM live migration; trustworthy execution environment; virtual machine; virtual machine monitor; Cloud computing; Degradation; Distributed computing; Fault tolerance; Grid computing; Protection; Security; Virtual machining; Virtual manufacturing; Voice mail; Live Migration; Privacy; Security; VMM-enforced Process Protection; Virtual Machine;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Trusted Infrastructure Technologies Conference, 2008. APTC '08. Third Asia-Pacific
Conference_Location :
Hubei
Print_ISBN :
978-0-7695-3363-6
Type :
conf
DOI :
10.1109/APTC.2008.15
Filename :
4683078
Link To Document :
بازگشت