首页> 外文学位 >Detection and Mitigation of Security Threats in Cloud Computing
【24h】

Detection and Mitigation of Security Threats in Cloud Computing

机译:检测和缓解云计算中的安全威胁

获取原文
获取原文并翻译 | 示例

摘要

Infrastructure-as-a-Service (IaaS) clouds provide computation and storage services to enterprises and individuals with increased elasticity and low cost. Cloud customers rent resources in the form of virtual machines (VMs). However, these VMs may face various security threats.;This dissertation proposes a new architectural framework, CloudMonatt , to detect and mitigate potential security threats targeting customers' VMs in cloud computing. CloudMonatt monitors the security health of VMs and attests to customers if they are getting their desired security. It takes actions to mitigate the potential threats that can compromise the security properties requested. We design cloud management and security services, and define new hardware-software modules in cloud servers to provide the underlying measurements. We define secure communications protocols to guarantee that the monitoring service takes place in an unforgeable way.;To demonstrate how CloudMonatt can enhance the VMs' security, we consider a variety of threats and their defenses that can be integrated in CloudMonatt. We first consider threats on resource availability. We design a set of memory Denial-of-Service (DoS) attacks: an attacker VM can abuse the shared memory resources to significantly degrade a victim VM's performance. Then we statistically monitor VMs' resource consumption behaviors to detect these attacks, and use resource throttling to mitigate the availability threats.;Next, we consider subtle attacks on confidentiality, specifically cache side-channel attacks. An attacker VM can exploit a shared CPU cache to steal information from the victim VM. We collect VMs' micro-architectural behaviors and use a combination of signature and anomaly detection techniques to identify the existence of various side-channel attacks. We use targeted VM migration to eliminate these confidentiality threats.;Then, we consider attacks on system integrity within a VM. We show how to protect a VM's system integrity from malware, using Virtual Machine Introspection (VMI) to passively collect information for malware detection and also actively change the VM's execution paths to defeat the potential malware.;In summary, CloudMonatt is a general-purpose architecture for providing VM security monitoring and protection to cloud customers. We hope CloudMonatt can be a foundation for future work on protecting VMs' security health in cloud computing.
机译:基础架构即服务(IaaS)云为企业和个人提供了增强的弹性和低成本的计算和存储服务。云客户以虚拟机(VM)的形式租用资源。然而,这些虚拟机可能面临着各种安全威胁。本文提出了一种新的架构框架CloudMonatt,用于检测和缓解针对客户在云计算中虚拟机的潜在安全威胁。 CloudMonatt监视VM的安全状况,并向客户证明其是否获得了所需的安全性。它采取措施来减轻可能威胁到所请求安全性的潜在威胁。我们设计云管理和安全服务,并在云服务器中定义新的硬件-软件模块以提供基础的度量。我们定义安全的通信协议以确保监视服务以不可伪造的方式发生。为了演示CloudMonatt如何增强VM的安全性,我们考虑了可以集成到CloudMonatt中的各种威胁及其防御措施。我们首先考虑对资源可用性的威胁。我们设计了一组内存拒绝服务(DoS)攻击:攻击者VM可以滥用共享内存资源,从而大大降低受害者VM的性能。然后,我们通过统计监视VM的资源消耗行为来检测这些攻击,并使用资源限制来缓解可用性威胁。接下来,我们考虑对机密性的细微攻击,特别是缓存侧通道攻击。攻击者VM可以利用共享的CPU缓存从受害VM中窃取信息。我们收集虚拟机的微体系结构行为,并结合使用签名和异常检测技术来识别各种侧通道攻击的存在。我们使用目标VM迁移来消除这些机密性威胁。然后,我们考虑对VM中的系统完整性进行攻击。我们展示了如何使用虚拟机内省(VMI)被动地收集信息以进行恶意软件检测,以及如何主动更改虚拟机的执行路径以击败潜在的恶意软件,从而保护虚拟机的系统完整性免受恶意软件的侵害。总而言之,CloudMonatt是通用的用于为云客户提供VM安全监视和保护的体系结构。我们希望CloudMonatt可以成为将来在云计算中保护VM的安全健康的基础。

著录项

  • 作者

    Zhang, Tianwei.;

  • 作者单位

    Princeton University.;

  • 授予单位 Princeton University.;
  • 学科 Computer engineering.
  • 学位 Ph.D.
  • 年度 2017
  • 页码 273 p.
  • 总页数 273
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号