Skip to main navigation Skip to search Skip to main content

Application-transparent live migration for virtual machine on network security enhanced hypervisor

  • Xianqin Chen*
  • , Xiaopeng Gao
  • , Han Wan
  • , Sumei Wang
  • , Xiang Long
  • *Corresponding author for this work
  • Beihang University

Research output: Contribution to journalArticlepeer-review

Abstract

As the number of Virtual Machines (VMs) consolidated on single physical server increases with the rapid advance of server hardware, virtual network turns complex and frangible. Modern Network Security Engines (NSE) are introduced to eradicate the intrusions occurring in the virtual network. In this paper, we point out the inadequacy of the present live migration implementation, which hinders itself from providing transparent VM relocation between hypervisors equipped with Network Security Engines (NSE-H). This occurs because the current implementation ignores VM-related Security Context (SC) required by NSEs embedded in NSE-H. We present the CoM, a comprehensive live migration framework, for NSE-H-based virtualization computing environment. We built a prototype system on Xen hypervisors to evaluate our framework, and conduct experiments under various realistic application environments. The results demonstrate that our solution successfully fixes the inadequacy of the present live migration implementation, and the performance overhead is negligible.

Original languageEnglish
Pages (from-to)32-42
Number of pages11
JournalChina Communications
Volume8
Issue number3
StatePublished - May 2011

Keywords

  • Live migration
  • Network security
  • Security context
  • Virtualization

Fingerprint

Dive into the research topics of 'Application-transparent live migration for virtual machine on network security enhanced hypervisor'. Together they form a unique fingerprint.

Cite this