An Access Control Model for Preventing Virtual Machine Escape Attack
Jiang Wu,
Zhou Lei,
Shengbo Chen and
Wenfeng Shen
Additional contact information
Jiang Wu: School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China
Zhou Lei: School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China
Shengbo Chen: School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China
Wenfeng Shen: School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China
Future Internet, 2017, vol. 9, issue 2, 1-19
Abstract:
With the rapid development of Internet, the traditional computing environment is making a big migration to the cloud-computing environment. However, cloud computing introduces a set of new security problems. Aiming at the virtual machine (VM) escape attack, we study the traditional attack model and attack scenarios in the cloud-computing environment. In addition, we propose an access control model that can prevent virtual machine escape (PVME) by adapting the BLP (Bell-La Padula) model (an access control model developed by D. Bell and J. LaPadula). Finally, the PVME model has been implemented on full virtualization architecture. The experimental results show that the PVME module can effectively prevent virtual machine escape while only incurring 4% to 8% time overhead.
Keywords: virtual security; virtual machine escape; access control; BLP model; PVME model (search for similar items in EconPapers)
JEL-codes: O3 (search for similar items in EconPapers)
Date: 2017
References: View complete reference list from CitEc
Citations:
Downloads: (external link)
https://www.mdpi.com/1999-5903/9/2/20/pdf (application/pdf)
https://www.mdpi.com/1999-5903/9/2/20/ (text/html)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:gam:jftint:v:9:y:2017:i:2:p:20-:d:100395
Access Statistics for this article
Future Internet is currently edited by Ms. Grace You
More articles in Future Internet from MDPI
Bibliographic data for series maintained by MDPI Indexing Manager ().