首页> 外文期刊>IEEE transactions on dependable and secure computing >Using Virtual Machine Allocation Policies to Defend against Co-Resident Attacks in Cloud Computing
【24h】

Using Virtual Machine Allocation Policies to Defend against Co-Resident Attacks in Cloud Computing

机译:使用虚拟机分配策略防御云计算中的共同居民攻击

获取原文
获取原文并翻译 | 示例
           

摘要

Cloud computing enables users to consume various IT resources in an on-demand manner, and with low management overhead. However, customers can face new security risks when they use cloud computing platforms. In this paper, we focus on one such threat—the co-resident attack, where malicious users build side channels and extract private information from virtual machines co-located on the same server. Previous works mainly attempt to address the problem by eliminating side channels. However, most of these methods are not suitable for immediate deployment due to the required modifications to current cloud platforms. We choose to solve the problem from a different perspective, by studying how to improve the virtual machine allocation policy, so that it is difficult for attackers to co-locate with their targets. Specifically, we (1) define security metrics for assessing the attack; (2) model these metrics, and compare the difficulty of achieving co-residence under three commonly used policies; (3) design a new policy that not only mitigates the threat of attack, but also satisfies the requirements for workload balance and low power consumption; and (4) implement, test, and prove the effectiveness of the policy on the popular open-source platform OpenStack.
机译:云计算使用户可以按需方式消耗各种IT资源,并且管理开销较低。但是,客户使用云计算平台时可能会面临新的安全风险。在本文中,我们将重点放在这种威胁上,即共存攻击,恶意用户在其中建立侧通道并从位于同一服务器上的虚拟机中提取私人信息。先前的工作主要试图通过消除副渠道来解决该问题。但是,由于需要对当前的云平台进行修改,因此这些方法中的大多数都不适合立即部署。我们选择从不同的角度来解决问题,方法是研究如何改进虚拟机分配策略,从而使攻击者难以与目标共同定位。具体来说,我们(1)定义用于评估攻击的安全指标; (2)对这些指标进行建模,并比较三种常用政策下实现共存的难度; (3)设计一种新的策略,不仅可以减轻攻击威胁,还可以满足工作负载平衡和低功耗的要求; (4)在流行的开源平台OpenStack上实施,测试和证明该政策的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号