The invention discloses a
virtual machine security
isolation system and method oriented to a multi-security-level
virtual desktop system and belongs to the field of
information security. According to the
virtual machine security
isolation system and method, three implementation stages including detection of abnormal user behaviors, migration of virtual machines and security isolation are conducted. The
virtual machine security isolation method comprises the steps that firstly, users of networks of the same security classification and virtual machines are bound together, and a user behavior feature
library is established through the similarity between the operation behaviors of the users of the networks of the same security classification; secondly, matching between real-time actual user behavior features and a historical user behavior feature liberty is conducted, the
threat level of the current operation of each user is worked out, a target host is selected and migrated, and the virtual machines with potential threats are migrated to a virtual
machine security isolation model for execution; finally, the virtual
machine security isolation model replaces the virtual machines to execute
system call required by the virtual
machine process. By the adoption of the virtual machine security isolation method oriented to the multi-security-level
virtual desktop system, the situation that the virtual machine process directly has access to resources of a
host machine system is avoided, the dependence of the virtual machine process on a kernel is reduced, the safety of the
host machine system is improved, and the purpose of security isolation of the virtual machines is achieved.