首页> 外文期刊>Future generation computer systems >CyberGuarder: A virtualization security assurance architecture for green cloud computing
【24h】

CyberGuarder: A virtualization security assurance architecture for green cloud computing

机译:Cyber​​Guarder:用于绿色云计算的虚拟化安全保证体系结构

获取原文
获取原文并翻译 | 示例
       

摘要

As the sizes of IT infrastructure continue to grow, cloud computing is a natural extension of virtualisation technologies that enable scalable management of virtual machines over a plethora of physically connected systems. The so-called virtualisation-based cloud computing paradigm offers a practical approach to green IT/douds, which emphasise the construction and deployment of scalable, energy-efficient network software applications {NetApp) by virtue of improved utilisation of the underlying resources. The latter is typically achieved through increased sharing of hardware and data in a multi-tenant cloud architecture/environment and, as such, accentuates the critical requirement for enhanced security services as an integrated component of the virtual infrastructure management strategy. This paper analyses the key security challenges faced by contemporary green cloud computing environments, and proposes a virtualisation security assurance architecture, CyberGuarder, which is designed to address several key security problems within the 'green' cloud computing context. In particular, CyberGuarder provides three different kinds of services; namely, a virtual machine security service, a virtual network security service and a policy based trust management service. Specifically, the proposed virtual machine security service incorporates a number of new techniques which include (1) a VMM-based integrity measurement approach for NetApp trusted loading, (2) a multi-granularity NetApp isolation mechanism to enable OS user isolation, and (3) a dynamic approach to virtual machine and network isolation for multiple NetApp's based on energy-efficiency and security requirements. Secondly, a virtual network security service has been developed successfully to provide an adaptive virtual security appliance deployment in a NetApp execution environment, whereby traditional security services such as IDS and firewalls can be encapsulated as VM images and deployed over a virtual security network in accordance with the practical configuration of the virtualised infrastructure. Thirdly, a security service providing policy based trust management is proposed to facilitate access control to the resources pool and a trust federation mechanism to support/optimise task privacy and cost requirements across multiple resource pools. Preliminary studies of these services have been carried out on our iVIC platform, with promising results. As part of our ongoing research in large-scale, energy-efficient/green cloud computing, we are currently developing a virtual laboratory for our campus courses using the virtualisation infrastructure of iVIC, which incorporates the important results and experience of CyberGuarder in a practical context.
机译:随着IT基础架构规模的不断扩大,云计算是虚拟化技术的自然扩展,可以通过大量物理连接的系统对虚拟机进行可扩展的管理。所谓的基于虚拟化的云计算范例为绿色IT /虚拟化提供了一种实用的方法,该方法强调了通过改进底层资源的利用来构建和部署可扩展的节能网络软件应用程序(NetApp)。后者通常是通过在多租户云架构/环境中增加硬件和数据的共享来实现的,因此,作为虚拟基础架构管理策略的集成组件,强调了增强安全服务的关键要求。本文分析了当今绿色云计算环境所面临的关键安全挑战,并提出了一种虚拟化安全保证体系结构Cyber​​Guarder,该体系结构旨在解决“绿色”云计算环境中的几个关键安全问题。特别是,Cyber​​Guarder提供了三种不同的服务:即,虚拟机安全服务,虚拟网络安全服务和基于策略的信任管理服务。具体来说,拟议的虚拟机安全服务结合了许多新技术,其中包括:(1)基于VMM的完整性测量方法用于NetApp可信加载;(2)多粒度NetApp隔离机制可实现OS用户隔离;以及(3) )基于能效和安全性要求的针对多个NetApp的虚拟机和网络隔离的动态方法。其次,虚拟网络安全服务已经成功开发,可以在NetApp执行环境中提供自适应的虚拟安全设备部署,从而可以将传统的安全服务(例如IDS和防火墙)封装为VM映像,并根据虚拟安全网络进行部署。虚拟化基础架构的实际配置。第三,提出了一种基于安全服务提供策略的信任管理,以促进对资源池的访问控制和信任联合机制,以支持/优化跨多个资源池的任务隐私和成本要求。这些服务已在我们的iVIC平台上进行了初步研究,并取得了可喜的成果。作为我们正在进行的有关大规模,节能/绿色云计算的研究的一部分,我们目前正在使用iVIC的虚拟化基础设施为校园课程开发虚拟实验室,该虚拟实验室在实践中结合了Cyber​​Guarder的重要成果和经验。 。

著录项

  • 来源
    《Future generation computer systems》 |2012年第2期|p.379-390|共12页
  • 作者单位

    School of Computer Sri. & Eng, Beihang University, Beijing. China;

    School of Computer Sri. & Eng, Beihang University, Beijing. China;

    School of Computer Sri. & Eng, Beihang University, Beijing. China;

    School of Computer Sri. & Eng, Beihang University, Beijing. China;

    School of Computer Sri. & Eng, Beihang University, Beijing. China;

    School of Computing and Mathematics, University of Derby, Derby, UK;

    School of Computing and Mathematics, Keele University, Keele, UK;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    cloud computing; green computing; virtualization; virtual security appliance; security isolation;

    机译:云计算;绿色计算;虚拟化;虚拟安全设备;安全隔离;
  • 入库时间 2022-08-18 02:17:05

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号