Verifying the Safety of Xen Security Modules

Wei Han, Yeping He and Liping Ding
Fifth International Conference on Secure Software Integration and Reliability Improvement, June 2011 Abstract:In virtualization environment, the communication and resource sharing between virtual machines can be protected by mandatory access control mechanism to guarantee the isolation of the virtual machines. The safety of the mandatory access control framework depends on whether the security sensitive operations are protected by the security check functions completely. In this paper, we present a novel method to verify the safety of the Xen security modules framework. We implement our method on the Xen 4.01 source code and evaluate the results. While our work in this paper focuses on the verification of Xen security modules, which can be used to analyze other mandatory access control framework analogous with it as well.
