跳到主要导航 跳到搜索 跳到主要内容

Seamless virtual machine live migration on network security enhanced hypervisor

  • Chen Xianqin*
  • , Wan Han
  • , Wang Sumei
  • , Long Xiang
  • *此作品的通讯作者

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Since the virtual network traffic is invisible outside the hypervisor, it is impossible for traditional network-base security devices to harness the attacks happened in virtual computing environment. Industry and academies adopt the network security enabled hypervisor (NSE-H) to protect virtual machines (VM) residing in the virtual network. In this paper, we identified the insufficiency of the existing live migration implementation, which prevents itself from providing transparent VM relocation between NSE-Hs. This occurs because the contemporary migration implementation only takes VM encapsulated states into account, but ignores VM related security context(SC) needed by NSE-H embedded security engines (SE). We presented a comprehensive live migration framework for the NSE-H, considering both the execution context encapsulated in VM instance and the VM related security context within the SEs. We built a prototype system of the framework based on stateful firewall enabled Xen hypervisor. Our experiment was performed with realistic applications and the results demonstrate that the solution complements the insufficiency without introducing significant performance downgrade. Even in the worst case, the downtime that occurs during migration increases no more than 15%, comparing to existing implementation.

源语言英语
主期刊名Proceedings of 2009 2nd IEEE International Conference on Broadband Network and Multimedia Technology, IEEE IC-BNMT2009
847-853
页数7
DOI
出版状态已出版 - 2009
活动2009 2nd IEEE International Conference on Broadband Network and Multimedia Technology, IEEE IC-BNMT2009 - Beijing, 中国
期限: 18 10月 200920 10月 2009

出版系列

姓名Proceedings of 2009 2nd IEEE International Conference on Broadband Network and Multimedia Technology, IEEE IC-BNMT2009

会议

会议2009 2nd IEEE International Conference on Broadband Network and Multimedia Technology, IEEE IC-BNMT2009
国家/地区中国
Beijing
时期18/10/0920/10/09

指纹

探究 'Seamless virtual machine live migration on network security enhanced hypervisor' 的科研主题。它们共同构成独一无二的指纹。

引用此