Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

Centralized Security Policy Support for Virtual Machine

For decades, researchers have pointed out that Mandatory Access Control (MAC) is an effective method to protect computer systems from being misused. Unfortunately, MAC is still not widely deployed because of its complexity. The problem is even worse in a virtual machine environment, because the current architecture is not designed to support MAC in a site-wide manner: machines with multiple virtual hosts needs to have multiple MAC security policies, and each of these policies must be updated and managed separately inside each virtual host.

In order to ease the burden on administrators when deploying security policies in a virtual environment, this paper proposes an architecture named Virtual Mandatory Access Control (VMAC) to centralize security policies, so that all policy management can easily be done from a central machine. VMAC securely centralizes the security logging information from all virtual hosts into a central machine so intrusion detection analysis on the logging data is straightforward.

To arrive at the architecture presented here, we have investigated various popular MAC schemes, and implemented several schemes with VMAC on the Xen Virtual Machine. This paper presents our experiences in the development process.

Nguyen Anh Quynh, Keio University

Ruo Ando, Keio University

Yoshiyasu Takefuji, Keio University

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {268770,
author = {Nguyen Anh Quynh and Ruo Ando and Yoshiyasu Takefuji},
title = {Centralized Security Policy Support for Virtual Machine},
booktitle = {20th Large Installation System Administration Conference (LISA 06)},
year = {2006},
address = {Washington, D.C.},
url = {https://www.usenix.org/conference/lisa-06/centralized-security-policy-support-virtual-machine},
publisher = {USENIX Association},
month = dec
}
Download

Presentation Video

Presentation Audio

MP3 Download OGG Download

Download Audio

Links

Paper: 
http://usenix.org/event/lisa06/tech/full_papers/quynh/quynh.pdf
Paper (HTML): 
http://usenix.org/event/lisa06/tech/full_papers/quynh/quynh_html/index.html
  • Log in or register to post comments

© USENIX
EIN 13-3055038

LISA is a registered trademark of the USENIX Association.

  • Privacy Policy
  • Contact Us