Skip to main navigation Skip to search Skip to main content

Seamless virtual machine live migration on network security enhanced hypervisor

  • Chen Xianqin*
  • , Wan Han
  • , Wang Sumei
  • , Long Xiang
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Since the virtual network traffic is invisible outside the hypervisor, it is impossible for traditional network-base security devices to harness the attacks happened in virtual computing environment. Industry and academies adopt the network security enabled hypervisor (NSE-H) to protect virtual machines (VM) residing in the virtual network. In this paper, we identified the insufficiency of the existing live migration implementation, which prevents itself from providing transparent VM relocation between NSE-Hs. This occurs because the contemporary migration implementation only takes VM encapsulated states into account, but ignores VM related security context(SC) needed by NSE-H embedded security engines (SE). We presented a comprehensive live migration framework for the NSE-H, considering both the execution context encapsulated in VM instance and the VM related security context within the SEs. We built a prototype system of the framework based on stateful firewall enabled Xen hypervisor. Our experiment was performed with realistic applications and the results demonstrate that the solution complements the insufficiency without introducing significant performance downgrade. Even in the worst case, the downtime that occurs during migration increases no more than 15%, comparing to existing implementation.

Original languageEnglish
Title of host publicationProceedings of 2009 2nd IEEE International Conference on Broadband Network and Multimedia Technology, IEEE IC-BNMT2009
Pages847-853
Number of pages7
DOIs
StatePublished - 2009
Event2009 2nd IEEE International Conference on Broadband Network and Multimedia Technology, IEEE IC-BNMT2009 - Beijing, China
Duration: 18 Oct 200920 Oct 2009

Publication series

NameProceedings of 2009 2nd IEEE International Conference on Broadband Network and Multimedia Technology, IEEE IC-BNMT2009

Conference

Conference2009 2nd IEEE International Conference on Broadband Network and Multimedia Technology, IEEE IC-BNMT2009
Country/TerritoryChina
CityBeijing
Period18/10/0920/10/09

Keywords

  • Hypervisor
  • Live migration
  • Network security
  • Virtualization

Fingerprint

Dive into the research topics of 'Seamless virtual machine live migration on network security enhanced hypervisor'. Together they form a unique fingerprint.

Cite this