Security Enhanced Virtual Machines An Introduction and Recipe
Manoj Kumar Srivastava · 2006
This paper, and the corresponding workshop, focusses on one of the major problem areas that any organization that is active on the Internet has to solve in order to conduct business in an increasingly hostile environment. The Discretionary Access Controls (DACs) that are the predominant Operating System (OS) techniques in mainstream OS’s for managing security make them highly vulnerable to cyber-attacks, since they lack the ability to introduce and enforce strong, system-wide, security policy based, system defenses. This paper details the need for Mandatory Access Control (MAC), the benefits of virtualized server platforms and strong compartmentalization, and walks through a step by step process of implementing such a security architecture on a modern Debian system. This walk through would entail configuring and compiling an virtual machine (the example is an User Mode Linux [UML] image, but the same mechanism can be adopted for Xen VMs as well), creating a base root file system for the UML image to run, and briefly touches on the networking configuration required to connect the virtual machine to the network.