DocumentCode :
3245736
Title :
DVM-MAC: A Mandatory Access Control System in Distributed Virtual Computing Environment
Author :
Zou, Deqing ; Shi, Lei ; Jin, Hai
Author_Institution :
Services Comput. Technol. & Syst. Lab., Huazhong Univ. of Sci. & Technol., Wuhan, China
fYear :
2009
fDate :
8-11 Dec. 2009
Firstpage :
556
Lastpage :
563
Abstract :
We design and implement a Mandatory Access Control (MAC) system in distributed virtual computing environment, named DVM-MAC, aiming to provide distributed trust through enforcing MAC policies. In DVM-MAC, Prioritized Chinese Wall (PCW) model is implemented to control potential covert channels between VMs in both single node and distributed environment. A policy enforcement module locates inside Xen VMM for better enforcing MAC locally rather than outside the VMM. DVM-MAC adopts centralized architecture for multi-level management and secure transmission of inter-node policy information. For performance consideration, a specific policy decision and enforcement module for controlling inter-node behaviors is moved out of Xen VMM and up to user space. DVM-MAC authorizes a specific center node named Central Security Server (CSS) to be responsible for the decision making between the nodes as well as leaves the inter-node policy enforcement module in each node. Through our experiments and data analysis, we verify the correctness, effectiveness, and efficiency in our prototype when implementing PCW model.
Keywords :
authorisation; software architecture; virtual machines; DVM-MAC; Xen VMM; central security server; distributed virtual computing environment; internode policy enforcement module; internode policy information transmission; mandatory access control system; multilevel management; prioritized chinese wall model; Access control; Concurrent computing; Distributed computing; Grid computing; Hardware; Operating systems; Resource virtualization; Virtual machining; Virtual manufacturing; Voice mail; Distributed System; Mandatory Access Control; Prioritized Chinese Wall Model; Virtual Machine;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Parallel and Distributed Systems (ICPADS), 2009 15th International Conference on
Conference_Location :
Shenzhen
ISSN :
1521-9097
Print_ISBN :
978-1-4244-5788-5
Type :
conf
DOI :
10.1109/ICPADS.2009.128
Filename :
5395344
Link To Document :
بازگشت