首页> 外文会议>IFIP Networking Conference >Trust-based grouping for cloud datacenters: Improving security in shared infrastructures
【24h】

Trust-based grouping for cloud datacenters: Improving security in shared infrastructures

机译:云数据中心的基于信任的分组:提高共享基础架构中的安全性

获取原文

摘要

Cloud computing can offer virtually unlimited resources without any upfront capital investment through a payper-use pricing model. However, the shared nature of multitenant cloud datacenter networks enables unfair or malicious use of the intra-cloud network by tenants, allowing attacks against the privacy and integrity of data and the availability of resources. In this paper, we introduce a resource allocation strategy that increases the security of network resource sharing among tenant applications. The key idea behind the strategy is to group applications of mutually trusting users into virtual infrastructures (logically isolated domains composed of a set of virtual machines as well as the virtual network interconnecting them). This provides some level of isolation and higher security. However, the use of groups may lead to fragmentation and negatively affect resource utilization. We study the associated trade-off and feasibility of the proposed approach. Evaluation results show the benefits of our strategy, which is able to offer better network resource protection against attacks with low extra cost.
机译:云计算可以通过按使用者付费的定价模型提供几乎无限的资源,而无需任何前期资本投资。但是,多租户云数据中心网络的共享性质使租户不公平或恶意使用云内网络,从而允许攻击数据的隐私和完整性以及资源的可用性。在本文中,我们介绍了一种资源分配策略,该策略可提高租户应用程序之间网络资源共享的安全性。该策略背后的关键思想是将相互信任的用户的应用程序分组为虚拟基础架构(由一组虚拟机以及将它们互连的虚拟网络组成的逻辑隔离域)。这提供了一定程度的隔离和更高的安全性。但是,使用组可能会导致碎片化,并对资源利用率产生负面影响。我们研究了相关权衡和拟议方法的可行性。评估结果显示了我们策略的优势,该策略能够以较低的额外成本为攻击提供更好的网络资源保护。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号