• DocumentCode
    3245736
  • Title

    DVM-MAC: A Mandatory Access Control System in Distributed Virtual Computing Environment

  • Author

    Zou, Deqing ; Shi, Lei ; Jin, Hai

  • Author_Institution
    Services Comput. Technol. & Syst. Lab., Huazhong Univ. of Sci. & Technol., Wuhan, China
  • fYear
    2009
  • fDate
    8-11 Dec. 2009
  • Firstpage
    556
  • Lastpage
    563
  • Abstract
    We design and implement a Mandatory Access Control (MAC) system in distributed virtual computing environment, named DVM-MAC, aiming to provide distributed trust through enforcing MAC policies. In DVM-MAC, Prioritized Chinese Wall (PCW) model is implemented to control potential covert channels between VMs in both single node and distributed environment. A policy enforcement module locates inside Xen VMM for better enforcing MAC locally rather than outside the VMM. DVM-MAC adopts centralized architecture for multi-level management and secure transmission of inter-node policy information. For performance consideration, a specific policy decision and enforcement module for controlling inter-node behaviors is moved out of Xen VMM and up to user space. DVM-MAC authorizes a specific center node named Central Security Server (CSS) to be responsible for the decision making between the nodes as well as leaves the inter-node policy enforcement module in each node. Through our experiments and data analysis, we verify the correctness, effectiveness, and efficiency in our prototype when implementing PCW model.
  • Keywords
    authorisation; software architecture; virtual machines; DVM-MAC; Xen VMM; central security server; distributed virtual computing environment; internode policy enforcement module; internode policy information transmission; mandatory access control system; multilevel management; prioritized chinese wall model; Access control; Concurrent computing; Distributed computing; Grid computing; Hardware; Operating systems; Resource virtualization; Virtual machining; Virtual manufacturing; Voice mail; Distributed System; Mandatory Access Control; Prioritized Chinese Wall Model; Virtual Machine;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel and Distributed Systems (ICPADS), 2009 15th International Conference on
  • Conference_Location
    Shenzhen
  • ISSN
    1521-9097
  • Print_ISBN
    978-1-4244-5788-5
  • Type

    conf

  • DOI
    10.1109/ICPADS.2009.128
  • Filename
    5395344