首页> 外文期刊>Journal of computer security >Towards automated security policy enforcement in multi-tenant virtual data centers
【24h】

Towards automated security policy enforcement in multi-tenant virtual data centers

机译:迈向多租户虚拟数据中心的自动化安全策略实施

获取原文
获取原文并翻译 | 示例

摘要

Virtual data centers allow the hosting of virtualized infrastructures (networks, storage, machines) that belong to several customers on the same physical infrastructure. Virtualization theoretically provides the capability for sharing the infrastructure among different customers. In reality, however, this is rarely (if ever) done because of security concerns. A major challenge in allaying such concerns is the enforcement of appropriate customer isolation as specified by high-level security policies. At the core of this challenge is the correct configuration of all shared resources on multiple machines to achieve this overall security objective.rnTo address this challenge, this paper presents a security architecture for virtual data centers based on virtualization and Trusted Computing technologies. Our architecture aims at automating the instantiation of a virtual infrastructure while automatically deploying the corresponding security mechanisms. This deployment is driven by a global isolation policy, and thus guarantees overall customer isolation across all resources. We have implemented a prototype of the architecture based on the Xen hypervisor.
机译:虚拟数据中心允许托管属于同一物理基础架构上的多个客户的虚拟化基础架构(网络,存储,机器)。理论上,虚拟化提供了在不同客户之间共享基础结构的功能。但是,实际上,出于安全考虑,很少(如果有的话)这样做。消除此类担忧的主要挑战是按照高级安全策略的规定实施适当的客户隔离。挑战的核心是在多台计算机上正确配置所有共享资源,以实现总体安全目标。为解决这一挑战,本文提出了一种基于虚拟化和可信计算技术的虚拟数据中心安全体系结构。我们的架构旨在自动化虚拟基础架构的实例,同时自动部署相应的安全机制。此部署由全局隔离策略驱动,因此可以保证所有资源之间的总体客户隔离。我们已经实现了基于Xen虚拟机管理程序的体系结构原型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号