DocumentCode
1843357
Title
A Prioritized Chinese Wall Model for Managing the Covert Information Flows in Virtual Machine Systems
Author
Cheng, Ge ; Jin, Hai ; Zou, Deqing ; Ohoussou, Alex K. ; Zhao, Feng
Author_Institution
Sch. of Comput. Sci. & Technol., Huazhong Univ. of Sci. & Technol., Wuhan
fYear
2008
fDate
18-21 Nov. 2008
Firstpage
1481
Lastpage
1487
Abstract
In virtual machine (VM) systems, mandatory access control (MAC) enforcement is possible now. This technique is both stronger and more flexible than traditional VM isolation, even if network communication is controlled. Unfortunately all of the VM systems with the MAC enforcement does not consider that the MAC controls may be distorted by covert channels, which constitute an important risk in VM systems. Traditional MAC models have difficulties being enforced to reduce the risk of covert flows in VM systems due to the many constraints and the lack of flexibility. In this paper, we identify access control requirements for managing covert channels in VM systems through a critical analysis of the ways by which classical models constrain the covert information flows and we propose a model called the prioritized Chinese wall model (PCW) to reduce the risk of covert flows in VM systems while preserving the flexibility. Furthermore, we enforce the policy in sHype/Xen VM system.
Keywords
authorisation; risk management; virtual machines; MAC enforcement; covert channel information flow management; covert flow risk reduction; critical analysis; mandatory access control; prioritized Chinese wall model; virtual machine system; Access control; Communication system control; Control systems; Grid computing; Hardware; Information management; Isolation technology; Risk management; Virtual machining; Virtual manufacturing;
fLanguage
English
Publisher
ieee
Conference_Titel
Young Computer Scientists, 2008. ICYCS 2008. The 9th International Conference for
Conference_Location
Hunan
Print_ISBN
978-0-7695-3398-8
Electronic_ISBN
978-0-7695-3398-8
Type
conf
DOI
10.1109/ICYCS.2008.534
Filename
4709192
Link To Document