Separation virtual machine monitors

  • Authors:
  • John McDermott;Bruce Montrose;Margery Li;James Kirby;Myong Kang

  • Affiliations:
  • Naval Research Laboratory, Washington, DC;Naval Research Laboratory, Washington, DC;Naval Research Laboratory, Washington, DC;Naval Research Laboratory, Washington, DC;Naval Research Laboratory, Washington, DC

  • Venue:
  • Proceedings of the 28th Annual Computer Security Applications Conference
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

Separation kernels are the strongest known form of separation for virtual machines. We agree with NSA's Information Assurance Directorate that while separation kernels are stronger than any other alternative, their construction on modern commodity hardware is no longer justifiable. This is because of orthogonal feature creep in modern platform hardware. We introduce the separation VMM as a response to this situation and explain how we prototyped one.