Virtual machines for enterprise desktop security

  • Authors:
  • Paul England;John Manferdelli

  • Affiliations:
  • Microsoft Corporation, 1 Microsoft Way, Redmond, Washington, USA;Microsoft Corporation, 1 Microsoft Way, Redmond, Washington, USA

  • Venue:
  • Information Security Tech. Report
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

A virtual machine monitor (VMM) allows a single computer to run two or more operating systems at the same time. VMMs are relatively simple and are typically built to high assurance standards, which means that the quality of isolation provided by a virtual machine monitor is usually greater than that which can be achieved with a general-purpose operating system. This paper discusses how the flexibility afforded by multiple OS environments and the robust isolation provided by a virtual machine monitor can be used to improve client PC security. A prototype system is also described. This paper is neither a product announcement nor an official Microsoft position paper, but rather it is a discussion of interesting configuration options that can be constructed using existing Microsoft and third-party products: in this case two or more operating systems running in conjunction with a virtual machine monitor.