Some ideas on virtualized system security, and monitors

6Citations
Citations of this article
6Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Virtualized systems such as Xen, VirtualBox, VMWare or QEmu have been proposed to increase the level of security achievable on personal computers. On the other hand, such virtualized systems are now targets for attacks. We propose an intrusion detection architecture for virtualized systems, and discuss some of the security issues that arise. We argue that a weak spot of such systems is domain zero administration, which is left entirely under the administrator's responsibility, and is in particular vulnerable to trojans. To avert some of the risks, we propose to install a role-based access control model with possible role delegation, and to describe all undesired activity flows through simple temporal formulas. We show how the latter are compiled into Orchids rules, via a fragment of linear temporal logic, through a generalization of the so-called history variable mechanism. © 2011 Springer-Verlag.

Cite

CITATION STYLE

APA

Benzina, H., & Goubault-Larrecq, J. (2011). Some ideas on virtualized system security, and monitors. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 6514 LNCS, pp. 244–258). Springer Verlag. https://doi.org/10.1007/978-3-642-19348-4_18

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free