This document proposes an access control model for virtual machine security called VBAC. It introduces elements like subjects, objects, access characteristics, security levels, and conflict sets. It improves the BLP model by adding trusted subjects and controlling the range of security levels. The model combines BLP, CW, and PCW policies. Rules are defined for access requests between VMs and resources based on these policies. Experimental results show the model's effectiveness in safely controlling resource and event behaviors in virtual machines.