首页> 外文会议>IEEE International conference on cloud computing >Improving Users' Isolation in IaaS: Virtual Machine Placement with Security Constraints
【24h】

Improving Users' Isolation in IaaS: Virtual Machine Placement with Security Constraints

机译:在IaaS中提高用户隔离度:具有安全约束的虚拟机放置

获取原文

摘要

Nowadays, virtualization is used as the sole mechanism to isolate different users on Cloud platforms. In this paper, we show that, due to improper virtualization of micro-architectural components, data leak and modification can occur on public Clouds. Furthermore, using the same vector, it is possible to induce performance interferences, i.e. noisy neighbors. Using this approach, a VM can steal resources from, and slow down, concurrent VMs. To counter this, we propose placement heuristics that take into account isolation requirements, thus allowing a user to specify the level of isolation he accepts, and with whom. We modify 3 classical heuristics to take into account these requirements. In addition, we propose 4 new heuristics that take into account the hierarchy of Cloud platforms and isolation requirements. Finally, we evaluate these heuristics and compare them with the modified classical ones. We show that our heuristics perform at least as well as the classical ones, while scaling better and being faster by a few orders of magnitude.
机译:如今,虚拟化已成为隔离Cloud平台上不同用户的唯一机制。在本文中,我们表明,由于微体系结构组件的不正确虚拟化,公共云上可能发生数据泄漏和修改。此外,使用相同的向量,有可能引起性能干扰,即嘈杂的邻居。使用这种方法,VM可以从并发VM窃取资源并降低其速度。为了解决这个问题,我们提出了考虑启发隔离要求的布局启发法,从而允许用户指定他接受的隔离级别以及与谁的隔离级别。考虑到这些要求,我们修改了3种经典启发式方法。此外,我们提出了4种新的启发式方法,其中考虑了云平台的层次结构和隔离要求。最后,我们评估这些启发式方法,并将其与改进的经典启发式方法进行比较。我们表明,启发式算法的性能至少与经典算法相同,而扩展性更好且速度提高了几个数量级。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号