Netinfo Security ›› 2016, Vol. 16 ›› Issue (10): 1-7.doi: 10.3969/j.issn.1671-1122.2016.10.001

• Orginal Article •     Next Articles

Design and Implementation on Multilevel Security Mandatory Access Control System for Virtual Machine Based on BLP

Yaping CHI1, Tingting JIANG1(), Chuping DAI2, Wei SUN1   

  1. 1. Communication Engineering Department, Beijing Electronic Science and Technology Institute, Beijing 100070, China
    2. School of Communications Engineering, Xidian University, Xi’an Shaanxi 710071, China;
  • Received:2016-08-16 Online:2016-10-31 Published:2020-05-13

Abstract:

Multilevel security is a mechanism that supports the simultaneous access of users and resources with different privileges, while ensuring that both users and resources can access the information that they have access to. In the cloud computing, the virtual machines that belonging to different users or enterprises may run on the same physical host, usually they have different levels of security. So it is very meaningful to implement multilevel secure access control policy to protect the virtual machine communication. In reaction to the phenomenon, mandatory access control security model that suitable for the virtual machine environment was built by modifying the model elements, security axioms and state transition rules of the traditional BLP security model. By using SELinux technology through shared memory and authorization table way, the multilevel security mandatory access control in the virtual environment was realized, that effectively enhance access security between the virtual machine and virtual machine with the host machine.

Key words: cloud computing, virtual machine, BLP, mandatory access control

CLC Number: