首页> 外文会议>International symposium on computer architecture >NoHype: Virtualized Cloud Infrastructure without the Virtualization
【24h】

NoHype: Virtualized Cloud Infrastructure without the Virtualization

机译:nohype:虚拟化云基础架构没有虚拟化

获取原文

摘要

Cloud computing is a disruptive trend that is changing the way we use computers. The key underlying technology in cloud infrastructures is virtualization - so much so that many consider virtualization to be one of the key features rather than simply an implementation detail. Unfortunately, the use of virtualization is the source of a significant security concern. Because multiple virtual machines run on the same server and since the virtualization layer plays a considerable role in the operation of a virtual machine, a malicious party has the opportunity to attack the virtualization layer. A successful attack would give the malicious party control over the all-powerful virtualization layer, potentially compromising the confidentiality and integrity of the software and data of any virtual machine. In this paper we propose removing the virtualization layer, while retaining the key features enabled by virtualization. Our NoHype architecture, named to indicate the removal of the hypervisor, addresses each of the key roles of the virtualization layer: arbitrating access to CPU, memory, and I/O devices, acting as a network device (e.g., Ethernet switch), and managing the starting and stopping of guest virtual machines. Additionally, we show that our NoHype architecture may indeed be "no hype" since nearly all of the needed features to realize the NoHype architecture are currently available as hardware extensions to processors and I/O devices.
机译:云计算是一种破坏性趋势,正在改变我们使用计算机的方式。云基础架构中的关键基础技术是虚拟化 - 如此多,因此许多人认为虚拟化是关键特征之一,而不是简单地实现详细信息。不幸的是,虚拟化的使用是重要的安全问题。由于多个虚拟机在同一服务器上运行并且由于虚拟化层在虚拟机的操作中播放相当大的作用,因此恶意方有机会攻击虚拟化层。成功的攻击将使恶意方控制全强虚拟化层,可能会影响任何虚拟机的软件和数据的机密性和完整性。在本文中,我们建议删除虚拟化层,同时保留虚拟化启用的关键功能。我们的Nohype架构,命名为指示虚拟机管理程序的删除,地址虚拟化层的每个关键角色:仲裁访问CPU,内存和I / O设备,充当网络设备(例如,以太网交换机),以及管理客户虚拟机的起始和停止。此外,我们表明,我们的Nohype架构可能确实可以是“无次次”,因为几乎所有要实现Nohype架构的所需功能当前都可以作为处理器和I / O设备的硬件扩展。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号