首页> 外文会议>International Conference on Information and Communications Security >PCA: Page Correlation Aggregation for Memory Deduplication in Virtualized Environments
【24h】

PCA: Page Correlation Aggregation for Memory Deduplication in Virtualized Environments

机译:PCA:虚拟化环境中的内存重复数据删除页面相关聚合

获取原文

摘要

To intelligently share limited memory across VMs in IaaS cloud, content-based page sharing (CBPS), like KSM, is utilized to greatly reduce the memory footprint of VMs. CBPS merges same-content pages into a single copy. However, it introduces some serious cross-VM covert channel threats. Besides, it has heavy overhead due to vast otiose operations, such as page comparisons and checksum calculations, when detecting page sharing opportunities. In this paper, we propose a novel memory deduplication approach called page correlation aggregation (PCA), which can efficiently reduce otiose operations. Meanwhile defends covert channels. One key idea of PCA is to divide VMs' pages into several sets, since pages with similar attributes have the greatest possibility with the same content. In PCA, the pages of VMs are firstly divided into different groups according to VMs' attributes. In each group pages are further separated into different classifications based on their access permissions. Thus page comparisons are restricted to the same classification for sharing. The other is that PCA introduces a dedicated cache to mitigate the latency of COW (Copy- On-Write) used for conducting covert channels. We have conducted a prototype on KSM, one popular CBPS technique. Our experimental results show that PCA reduces otiose operations about 40%, and can effectively resist covert channels.
机译:在IAAS云中跨越VMS智能共享有限的内存,基于内容的页面共享(CBP),如KSM,以大大降低VM的内存占用空间。 CBPS将相同内容页面合并到单个副本中。但是,它介绍了一些严重的跨VM隐蔽渠道威胁。此外,由于巨大的偏离操作,例如页面比较和校验和计算,检测页面共享机会时,它具有繁重的开销。在本文中,我们提出了一种名为Page相关聚合(PCA)的新型记忆重复数据删除方法,其可以有效地降低OTIOSE操作。同时捍卫隐蔽渠道。 PCA的一个关键概念是将VMS的页面划分为多个集合,因为具有类似属性的页面具有相同内容的最大可能性。在PCA中,VM的页面首先划分为根据VMS属性的不同组。在每个组页面中,进一步基于其访问权限分离为不同的分类。因此,页面比较仅限于相同的分类分类。另一种是PCA引入了专用缓存,以减轻用于进行封面通道的牛的等待时间(写入写入)。我们在KSM上进行了一种原型,一种流行的CBPS技术。我们的实验结果表明,PCA减少了大约40%的右侧操作,可以有效地抵抗封面通道。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号