【24h】

Disk storage isolation and verification in cloud

机译:云中的磁盘存储隔离和验证

获取原文

摘要

Multi-tenancy of the cloud maximizes the utility of computation and storage resources by multiplexing the underlying hardware infrastructure amongst cloud customers; however, it also introduces significant security issues such as information leakage between two virtual machines (VMs) even if certain access control policy (e.g., Chinese Wall security policy) has been deployed in the cloud. Physical resource isolation between VMs is an effective mechanism to remove the covert channels in the cloud and prevent information leakage; however, due to economic concerns or negligence, some cheap-and-lazy cloud providers are not motivated to enforce the physical resource isolation as they promised. In this paper, we first develop a mechanism to check the co-residency of two files on local hard disk(s) by measuring the file access time, and then extend our mechanism to check data storage co-residency on Amazon S3 cloud storage.
机译:通过在云客户之间复用基础硬件基础架构,云的多租户可最大程度地提高计算和存储资源的利用率。但是,即使在云中部署了某些访问控制策略(例如,Chinese Wall安全策略),它也会带来严重的安全问题,例如两个虚拟机(VM)之间的信息泄漏。虚拟机之间的物理资源隔离是一种有效的机制,可以消除云中的隐秘通道并防止信息泄漏;但是,由于经济上的担忧或疏忽,一些廉价和懒惰的云提供商没有动力去实现他们所承诺的物理资源隔离。在本文中,我们首先开发一种机制,通过测量文件访问时间来检查本地硬盘上两个文件的共存,然后扩展我们的机制以检查Amazon S3云存储上的数据存储共存。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号