首页> 外文期刊>IEEE transactions on information forensics and security >Using Mussel-Inspired Self-Organization and Account Proxies to Obfuscate Workload Ownership and Placement in Clouds
【24h】

Using Mussel-Inspired Self-Organization and Account Proxies to Obfuscate Workload Ownership and Placement in Clouds

机译:使用受贻贝启发的自我组织和帐户代理来混淆云中的工作负载所有权和位置

获取原文
获取原文并翻译 | 示例
           

摘要

Recent research has provided evidence indicating how a malicious user could perform coresidence profiling and public-to-private IP mapping to target and exploit customers which share physical resources. The attacks rely on two steps: resource placement on the target's physical machine and extraction. Our proposed solution, in part inspired by mussel self-organization, relies on user account and workload clustering to mitigate coresidence profiling. Users with similar preferences and workload characteristics are mapped to the same cluster. To obfuscate the public-to-private IP map, each cluster is managed and accessed by an account proxy. Each proxy uses one public IP address, which is shared by all clustered users when accessing their instances, and maintains the mapping to private IP addresses. We describe a set of capabilities and attack paths an attacker needs to execute for targeted coresidence, and present arguments to show how our approach disrupts the critical steps in the attack path for most cases. We then perform a risk assessment to determine the likelihood an individual user will be victimized, given that a successful nondirected exploit has occurred. Our results suggest that while possible, this event is highly unlikely.
机译:最近的研究提供了证据,表明恶意用户如何执行机密性概要分析和公私IP映射,以瞄准和利用共享物理资源的客户。攻击取决于两个步骤:将资源放置在目标物理计算机上和提取。我们提出的解决方案部分受贻贝自组织的启发,它依赖于用户帐户和工作负载聚类来减轻核心支持性能分析。具有相似首选项和工作负载特征的用户将映射到同一群集。为了模糊公共到私有IP映射,每个群集都由帐户代理进行管理和访问。每个代理使用一个公用IP地址,所有群集用户在访问其实例时都共享该公用IP地址,并维护到专用IP地址的映射。我们描述了攻击者针对目标机芯需要执行的一组功能和攻击路径,并提供了论据以说明在大多数情况下我们的方法如何破坏攻击路径中的关键步骤。然后,我们将进行风险评估,以确定单个用户遭受受害者攻击的可能性,前提是成功进行了非定向攻击。我们的结果表明,尽管可能,但此事件极不可能发生。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号