Live migration is an essential feature of virtualization that allows transfer of virtual machine from one physical server to another without interrupting the services running in virtual machine. Live migration facilitates workload balancing, fault tolerance, online system maintenance, consolidation of virtual machines etc. Unfortunately the disclosed vulnerabilities with the live migration pose significant security risks. Because of these security risks the industry is hesitant to adapt the technology for sensitive applications. This paper is an investigation of attacks on live migration of virtual machine and discusses the key proposed and implemented approaches to secure live migration.
Server virtualization is an emerging technology that provides efficient resource utilization and cost-saving benefits. It consolidates many physical servers into a single physical server saving the hardware resources, physical space, power-consumption, air conditioning capacity and man power to manage the servers. Thus virtualization assists "Green Technology". Live migration is an essential feature of virtualization that allows transition of a running virtual machine from one system to another without halting the virtual machine. Live migration extends the list of benefits server virtualization provides. Almost all virtualization softwares now include support for live migration of virtual machine. Live migration is in its infant stage where security of live migration is yet to be analyzed. The usages of live migration and security exploits over it have both increased over time. The security concern of live migration is a major factor for its adoption by the IT industry. In this paper we discuss the attack model on the virtualization system and design and implement a security framework for secure live migration of virtual machines. The framework is an integrated security solution that addresses role based access policy, network intrusion, firewall protection and encryption for secure live migration process.
Keywordslive migration, live migration security, live migration attack model, role based access control policy, reactive IDS, inter VM attacks.I.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.