计算机科学与探索 ›› 2011, Vol. 5 ›› Issue (5): 452-457.

• 学术研究 • 上一篇    下一篇

虚拟机动态迁移中的安全分析

蒋学渊, 李明禄, 翁楚良   

  1. 上海交通大学 计算机科学与工程系, 上海 200240
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2011-05-01 发布日期:2011-05-01

Security Analysis in Virtual Machine Live Migration

JIANG Xueyuan, LI Minglu, WENG Chuliang   

  1. Department of Computer Science and Engineering, Shanghai Jiao Tong University, Shanghai 200240, China
  • Received:1900-01-01 Revised:1900-01-01 Online:2011-05-01 Published:2011-05-01

摘要: 网络计算与“云计算”兴起过程中, 其基础技术虚拟化技术发展迅速。计算机虚拟化的动态迁移, 是重要的虚拟化应用功能。基础的动态迁移协议较简单, 存在安全可信的隐患。在Xen虚拟化的平台下, 测试了现有虚拟化动态迁移组件的使用对动态迁移本身的性能影响, 提供了基于网络嗅探及地址解析协议(address resolution protocol, ARP)欺骗技术的攻击方案, 验证了其安全防护能力的不足, 提出了解决方案。

关键词: 虚拟机, 动态迁移, 安全问题

Abstract: During the development of network computing and cloud computing, virtualization grows up quickly as the base technology. Virtualization live migration is an important feature for applications based on virtualization. Basic live migration protocol is too simple, and security hazard exists. Based on Xen virtualization platform, the performance of existed security solutions and the influence to live migration of these solutions are tested. The weakness of existed solutions is shown by attack based on sniffer and address resolution protocol (ARP) spoofing. The idea of solving the new problem is given.

Key words: virtual machine, live migration, security problem