首页> 外文会议>ACM symposium on operating systems principles >CloudVisor: Retrofitting Protection of Virtual Machines in Multi-tenant Cloud with Nested Virtualization
【24h】

CloudVisor: Retrofitting Protection of Virtual Machines in Multi-tenant Cloud with Nested Virtualization

机译:CloudVisor:用嵌套虚拟化改造多租户云中虚拟机的保护

获取原文

摘要

Multi-tenant cloud, which usually leases resources in the form of virtual machines, has been commercially available for years. Unfortunately, with the adoption of commodity virtualized infrastructures, software stacks in typical multi-tenant clouds are non-trivially large and complex, and thus are prone to compromise or abuse from adversaries including the cloud operators, which may lead to leakage of security-sensitive data. In this paper, we propose a transparent, backward-compatible approach that protects the privacy and integrity of customers' virtual machines on commodity virtualized infrastructures, even facing a total compromise of the virtual machine monitor (VMM) and the management VM. The key of our approach is the separation of the resource management from security protection in the virtualization layer. A tiny security monitor is introduced underneath the commodity VMM using nested virtualization and provides protection to the hosted VMs. As a result, our approach allows virtualization software (e.g., VMM, management VM and tools) to handle complex tasks of managing leased VMs for the cloud, without breaking security of users' data inside the VMs. We have implemented a prototype by leveraging commercially-available hardware support for virtualization. The prototype system, called CloudVisor, comprises only 5.5K LOCs and supports the Xen VMM with multiple Linux and Windows as the guest OSes. Performance evaluation shows that CloudVisor incurs moderate slowdown for I/O intensive applications and very small slowdown for other applications.
机译:多租户云,通常在虚拟机形式租用资源,已商业上可用。遗憾的是,随着商品虚拟化基础设施的采用,典型的多租户云中的软件堆栈是非琐碎的大而复杂的,因此易于妥协或滥用来自包括云运算符的对手,这可能导致安全敏感的泄漏数据。在本文中,我们提出了一种透明,向后兼容的方法,可以保护客户虚拟机的隐私和完整性在商品虚拟化基础架构上,甚至面临虚拟机监视器(VMM)和管理VM的总妥协。我们方法的关键是在虚拟化层中的安全保护中分离资源管理。使用嵌套虚拟化在商品VMM下面引入微小安全监视器,并为托管VM提供保护。因此,我们的方法允许虚拟化软件(例如,VMM,Management VM和Tools)来处理管理云的租用VM的复杂任务,而不会破坏VM内用户数据的安全性。我们通过利用商业上可用的硬件支持来实现了一种原型的虚拟化。称为CloudVisor的原型系统仅包含5.5K个LOC,并支持具有多个Linux和Windows的Xen VMM作为访客操作系统。绩效评估表明,CloudVisor为I / O密集型应用程序进行了适度的放缓,以及其他应用程序非常小的放缓。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号