首页> 外文会议>IEEE Global Communications Conference >Cache Covert-Channel Mitigation in Cloud Virtualization with XEN's Credit Scheduler
【24h】

Cache Covert-Channel Mitigation in Cloud Virtualization with XEN's Credit Scheduler

机译:使用XEN的Credit Scheduler缓解云虚拟化中的缓存隐蔽通道

获取原文

摘要

Covert- and side-channels as well as techniques to establish them in cloud computing are in focus of research for quite some time. However, not many concrete mitigation methods have been developed and even less have been adapted and concretely implemented by cloud providers. Thus, we recently conceptually proposed C3-Sched a CPU scheduling based approach to mitigate L2 cache covert-channels. Instead of flushing the cache on every context switch, we schedule trusted virtual machines to create noise which prevents potential covert-channels. Additionally, our approach aims on preserving performance by utilizing existing instead of artificial workload while reducing covert-channel related cache flushes to cases where not enough noise has been achieved. In this work we evaluate cache covert-channel mitigation and performance impact of our integration of C3-Sched in the XEN credit scheduler. Moreover, we compare it to naive solutions and more competitive approaches.
机译:隐蔽通道和辅助通道以及在云计算中建立隐蔽通道和辅助通道的技术已成为相当长一段时间的研究重点。但是,尚未开发出许多具体的缓解方法,而云提供商已采用和具体实施的缓解方法则更少。因此,我们最近在概念上提出了C 3 -Sched一种基于CPU调度的方法来减轻L2缓存隐蔽通道。我们没有调度每个上下文切换上的缓存,而是调度受信任的虚拟机来创建噪声,以防止潜在的隐蔽通道。此外,我们的方法旨在通过利用现有工作负载(而不是人为工作负载)来保持性能,同时将与隐蔽通道相关的缓存刷新减少到未实现足够噪声的情况。在这项工作中,我们评估了XEN信用调度程序中C 3 -Sched集成对缓存隐蔽通道的缓解作用以及对性能的影响。此外,我们将其与幼稚的解决方案和更具竞争力的方法进行了比较。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号