Separation virtual machine monitors

@inproceedings{McDermott2012SeparationVM,
  title={Separation virtual machine monitors},
  author={John P. McDermott and Bruce E. Montrose and Margery Li and James Kirby and Myong H. Kang},
  booktitle={ACSAC},
  year={2012}
}
Separation kernels are the strongest known form of separation for virtual machines. We agree with NSA's Information Assurance Directorate that while separation kernels are stronger than any other alternative, their construction on modern commodity hardware is no longer justifiable. This is because of orthogonal feature creep in modern platform hardware. We… CONTINUE READING