Confining Windows Inter-Process Communications for OS-Level Virtual Machine

Proceedings of the 1st EuroSys Workshop on Virtualization Technology for Dependable Systems(2016)

引用 15|浏览41
暂无评分
摘要
As OS-level virtualization technology usually imposes little overhead on virtual machine start-up and running, it provides an excellent choice for building intrusion/fault tolerant applications that require redundancy and frequent invocation. When developing Windows OS-level virtual machine, however, people will inevitably face the challenge of confining Windows Inter-Process Communications (IPC). As IPC on Windows platform is more complex than UNIX style OS and most of the programs on Windows are not open-source, it is difficult to discover all of the performed IPCs and confine them. In this paper, we propose three general principles to confine IPC on Windows OS and a novel IPC confinement mechanism based on the principles. With the mechanism, for the first time from the literature, we successfully virtualized RPC System Service (RPCSS) and Internet Information Server (IIS) on Feather-weight Virtual Machine (FVM). Experimental results demonstrate that multiple IIS web server instances can simultaneously run on single Windows OS with much less performance overhead than other popular VM technology, offering a good basis for constructing dependable system.
更多
查看译文
关键词
os-level virtualization technology,single windows os,windows platform,virtual machine,windows os-level virtual machine,inter-process communication,multiple iis web server,popular vm technology,windows os,confining windows,ipc confinement,performance overhead,dependable system,novel ipc confinement mechanism,confining windows inter-process communications,inter process communication,fault tolerant
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要