• DocumentCode
    2651428
  • Title

    A Virtualization Assurance Language for Isolation and Deployment

  • Author

    Bleikertz, Sören ; Gross, T.

  • fYear
    2011
  • fDate
    6-8 June 2011
  • Firstpage
    33
  • Lastpage
    40
  • Abstract
    Cloud computing and virtualized infrastructures are often accompanied by complex configurations and topologies. Dynamic scaling, rapid virtual machine deployment, and open multi-tenant architectures create an environment, in which local misconfiguration can create subtle security risks for the entire infrastructure. This situation calls for automated deployment as well as analysis mechanisms, which in turn require a cloud assurance policy language to express security goals for such environments. Where possible, configuration changes should be statically checked against the policy prior to implementation on the infrastructure. We study security requirements of virtualized infrastructures and propose a practical tool-independent policy language for security assurance. Our policy proposal has a formal foundation, and still allows for efficient specification of a variety of security goals, such as isolation. In addition, we offer language provisions to compare a desired state against an actual state, discovered in the configuration, and thus allow for a differential analysis. The language is well-suited for automated deduction, be it by model checking or theorem proving.
  • Keywords
    cloud computing; computer network security; formal specification; formal verification; specification languages; theorem proving; virtual machines; virtual private networks; virtualisation; automated deployment; cloud assurance policy language; cloud computing; dynamic scaling; formal specification; model checking; open multitenant architectures; rapid virtual machine deployment; security requirements; theorem proving; virtualization assurance language; virtualized infrastructures; Complexity theory; Redundancy; Resilience; Security; Topology; Virtual machine monitors; Virtual machining;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Policies for Distributed Systems and Networks (POLICY), 2011 IEEE International Symposium on
  • Conference_Location
    Pisa
  • Print_ISBN
    978-1-4244-9879-6
  • Electronic_ISBN
    978-0-7695-4330-7
  • Type

    conf

  • DOI
    10.1109/POLICY.2011.10
  • Filename
    5976793