首页> 外文期刊>Communications, China >An effective and scalable VM migration strategy to mitigate cross-VM side-channel attacks in cloud
【24h】

An effective and scalable VM migration strategy to mitigate cross-VM side-channel attacks in cloud

机译:一种有效且可扩展的VM迁移策略,可缓解云中的跨VM侧通道攻击

获取原文
获取原文并翻译 | 示例
       

摘要

Co-residency of virtual machines (VMs) of different tenants on the same physical platform would possibly lead to cross-VM side-channel attacks in the cloud. While most of current countermeasures fail for real or immediate deployment due to their requirement for modification of virtualization structure, we adopt dynamic migration, an inherent mechanism of the cloud platform, as a general defense against this kind of threats. To this end, we first set up a unified practical information leakage model which shows the factors affecting side channels and describes the way they influence the damage due to side-channel attacks. Since migration is adopted to limit the time duration of co-residency, we envision this defense as an optimization problem by setting up an Integer Linear Programming (ILP) to calculate optimal migration strategy, which is intractable due to high computational complexity. Therefore, we approximate the ILP with a baseline genetic algorithm, which is further improved for its optimality and scalability. Experimental results show that our migration-based defense can not only provide excellent security guarantees and affordable performance cost in both theoretical simulation and practical cloud environment, but also achieve better optimality and scalability than previous countermeasures.
机译:同一物理平台上不同租户的虚拟机(VM)的共存可能会导致云中跨VM的旁通道攻击。尽管当前大多数对策由于需要修改虚拟化结构而无法立即或立即部署,但我们采用动态迁移(云平台的固有机制)作为抵御此类威胁的常规措施。为此,我们首先建立了一个统一的实用信息泄漏模型,该模型显示了影响边道的因素并描述了它们影响边道攻击造成的破坏的方式。由于采用迁移来限制共同居住的时间,因此我们通过设置整数线性规划(ILP)来计算最佳迁移策略来将这种防御视为一个优化问题,由于计算复杂度高,因此难以解决。因此,我们用基线遗传算法对ILP进行了近似,其最优性和可扩展性得到了进一步改进。实验结果表明,基于迁移的防御不仅可以在理论模拟和实际云环境中提供出色的安全保证和可承受的性能成本,而且比以前的对策具有更好的优化性和可扩展性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号