A separation model for virtual machine monitors | IEEE Conference Publication | IEEE Xplore