首页> 外文会议>IEEE International Performance Computing and Communications Conference >Mitigating cloud co-resident attacks via grouping-based virtual machine placement strategy
【24h】

Mitigating cloud co-resident attacks via grouping-based virtual machine placement strategy

机译:通过基于分组的虚拟机放置策略缓解云共存攻击

获取原文

摘要

Security is one of the biggest concerns for the further adoption of Clouds. However, Cloud providers usually assign VMs leased by different customers upon the same physical server. Albeit maximizing resource efficiency, this cross-domain sharing poses a serious threat to customers' privacy concerns. A malicious VM could break or bypass the isolation mechanism and execute certain cross-VM attacks, such as side channel attacks or memory Dos attacks, etc. However, most of previous solutions are either attack-specific or unsuitable for immediate deployment, making the mitigation techniques for co-resident attacks still an important and worth-studying problem in cloud security. In this paper, we propose a novel grouping-based VM placement strategy to provide a secure optimization for existing VM placement policies. The theoretical analysis and simulation results show that our strategy decreases enormously the probability of co-residence while incurring only a slight loss on resource efficiency. The results also demonstrate that our strategy is significantly more effective in terms of both co-location resistance and resources efficiency, compared with the CLR policy.
机译:安全性是进一步采用云技术的最大问题之一。但是,云提供商通常会将不同客户租用的VM分配到同一台物理服务器上。尽管最大程度地提高了资源效率,但这种跨域共享对客户的隐私问题构成了严重威胁。恶意VM可能破坏或绕过隔离机制,并执行某些跨VM攻击,例如边信道攻击或内存Dos攻击等。但是,以前的大多数解决方案都是特定于攻击的,或者不适合立即部署,因此可以缓解共存攻击的技术仍然是云安全中一个重要且值得研究的问题。在本文中,我们提出了一种基于分组的新颖VM放置策略,以为现有VM放置策略提供安全的优化。理论分析和仿真结果表明,我们的策略大大降低了共存的可能性,而对资源效率的影响却很小。结果还表明,与CLR政策相比,我们的策略在共址阻力和资源效率方面都更加有效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号