DocumentCode :
1843357
Title :
A Prioritized Chinese Wall Model for Managing the Covert Information Flows in Virtual Machine Systems
Author :
Cheng, Ge ; Jin, Hai ; Zou, Deqing ; Ohoussou, Alex K. ; Zhao, Feng
Author_Institution :
Sch. of Comput. Sci. & Technol., Huazhong Univ. of Sci. & Technol., Wuhan
fYear :
2008
fDate :
18-21 Nov. 2008
Firstpage :
1481
Lastpage :
1487
Abstract :
In virtual machine (VM) systems, mandatory access control (MAC) enforcement is possible now. This technique is both stronger and more flexible than traditional VM isolation, even if network communication is controlled. Unfortunately all of the VM systems with the MAC enforcement does not consider that the MAC controls may be distorted by covert channels, which constitute an important risk in VM systems. Traditional MAC models have difficulties being enforced to reduce the risk of covert flows in VM systems due to the many constraints and the lack of flexibility. In this paper, we identify access control requirements for managing covert channels in VM systems through a critical analysis of the ways by which classical models constrain the covert information flows and we propose a model called the prioritized Chinese wall model (PCW) to reduce the risk of covert flows in VM systems while preserving the flexibility. Furthermore, we enforce the policy in sHype/Xen VM system.
Keywords :
authorisation; risk management; virtual machines; MAC enforcement; covert channel information flow management; covert flow risk reduction; critical analysis; mandatory access control; prioritized Chinese wall model; virtual machine system; Access control; Communication system control; Control systems; Grid computing; Hardware; Information management; Isolation technology; Risk management; Virtual machining; Virtual manufacturing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Young Computer Scientists, 2008. ICYCS 2008. The 9th International Conference for
Conference_Location :
Hunan
Print_ISBN :
978-0-7695-3398-8
Electronic_ISBN :
978-0-7695-3398-8
Type :
conf
DOI :
10.1109/ICYCS.2008.534
Filename :
4709192
Link To Document :
بازگشت