首页> 外文会议>IEEE International Conference on Cloud Computing >A Cross-Virtual Machine Network Channel Attack via Mirroring and TAP Impersonation
【24h】

A Cross-Virtual Machine Network Channel Attack via Mirroring and TAP Impersonation

机译:通过镜像和TAP模拟的跨虚拟机网络通道攻击

获取原文

摘要

Data privacy and security is a leading concern for providers and customers of cloud computing, where Virtual Machines (VMs) can co-reside within the same underlying physical machine. Side channel attacks within multi-tenant virtualized cloud environments are an established problem, where attackers are able to monitor and exfiltrate data from co-resident VMs. Virtualization services have attempted to mitigate such attacks by preventing VM-to-VM interference on shared hardware by providing logical resource isolation between co-located VMs via an internal virtual network. However, such approaches are also insecure, with attackers capable of performing network channel attacks which bypass mitigation strategies using vectors such as ARP Spoofing, TCP/IP steganography, and DNS poisoning. In this paper we identify a new vulnerability within the internal cloud virtual network, showing that through a combination of TAP impersonation and mirroring, a malicious VM can successfully redirect and monitor network traffic of VMs co-located within the same physical machine. We demonstrate the feasibility of this attack in a prominent cloud platform - OpenStack - under various security requirements and system conditions, and propose countermeasures for mitigation.
机译:数据隐私和安全性是云计算提供商和客户最关注的问题,因为虚拟机(VM)可以共存于同一基础物理机中。多租户虚拟化云环境中的侧通道攻击是一个既定问题,攻击者能够从共同驻留的VM监视和窃取数据。虚拟化服务已经尝试通过通过内部虚拟网络在位于同一位置的虚拟机之间提供逻辑资源隔离来防止虚拟机对虚拟机对共享硬件的干扰来减轻此类攻击。但是,这种方法也不安全,攻击者能够执行网络信道攻击,而使用诸如ARP欺骗,TCP / IP隐写术和DNS中毒之类的媒介绕过缓解策略。在本文中,我们确定了内部云虚拟网络中的一个新漏洞,表明通过TAP模拟和镜像的组合,恶意VM可以成功重定向和监视位于同一物理计算机中的VM的网络流量。我们在各种安全要求和系统条件下,在著名的云平台OpenStack中演示了此攻击的可行性,并提出了缓解措施。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号