Publication | Closed Access
A Prioritized Chinese Wall Model for Managing the Covert Information Flows in Virtual Machine Systems
15
Citations
11
References
2008
Year
Unknown Venue
EngineeringInformation SecurityInformation ForensicsSoftware EngineeringConfidential ComputingSide-channel AttackHardware SecuritySystems EngineeringNetwork SecurityAccess Control RequirementsVirtualization SecurityComputer EngineeringComputer ScienceCovert ChannelData SecurityCryptographyVirtual Machine SystemsCloud ComputingVirtualization ToolSystem SoftwareCovert Information FlowsMandatory Access ControlVirtual Machine
In virtual machine (VM) systems, mandatory access control (MAC) enforcement is possible now. This technique is both stronger and more flexible than traditional VM isolation, even if network communication is controlled. Unfortunately all of the VM systems with the MAC enforcement does not consider that the MAC controls may be distorted by covert channels, which constitute an important risk in VM systems. Traditional MAC models have difficulties being enforced to reduce the risk of covert flows in VM systems due to the many constraints and the lack of flexibility. In this paper, we identify access control requirements for managing covert channels in VM systems through a critical analysis of the ways by which classical models constrain the covert information flows and we propose a model called the Prioritized Chinese Wall model (PCW) to reduce the risk of covert flows in VM systems while preserving the flexibility. Furthermore, we enforce the policy in sHype/Xen VM system.
| Year | Citations | |
|---|---|---|
Page 1
Page 1