首页> 外文期刊>Parallel and Distributed Systems, IEEE Transactions on >On Mitigating the Risk of Cross-VM Covert Channels in a Public Cloud
【24h】

On Mitigating the Risk of Cross-VM Covert Channels in a Public Cloud

机译:关于减轻公共云中跨VM隐蔽通道的风险

获取原文
获取原文并翻译 | 示例

摘要

Virtualization is one of the key enablers in cloud computing. At the same time, though, it is also widely considered as a double-edged sword that may cause information leakage between virtual machines (VM) co-residing on the same physical server via various cross-VM covert channels. In this paper, we first explore the impact of different bystander workloads on cross-VM covert channels. Then, we use a Continuous Time Markov Process to model the impact of bystanders on the cross-VM covert channel in terms of both the work scheduling of the virtualization platform and the intensity of the bystander workloads. Based on empirical study, we quantify the relationship between the influential factors and the transmission quality of the covert channel. A tailored and lightweight VM provisioning strategy, which aims to ensure that bystander workloads on each server can cause sufficiently high error rates to covert channels, is proposed to mitigate the threat of cross-VM covert channels while maintaining the resource efficiency of virtualization. The efficiency and efficacy of the proposed VM provisioning strategy is evaluated through trace-driven simulations.
机译:虚拟化是云计算中的关键推动力之一。但是,与此同时,它也被广泛认为是一把双刃剑,它可能会通过各种跨VM隐蔽通道在同一物理服务器上共存的虚拟机(VM)之间造成信息泄漏。在本文中,我们首先探讨了不同的旁观者工作负载对跨VM隐藏通道的影响。然后,我们使用连续时间马尔可夫过程,根据虚拟化平台的工作计划和旁观者工作负载的强度,对旁观者对跨VM隐蔽渠道的影响进行建模。在实证研究的基础上,我们对影响因素与隐蔽通道传输质量之间的关系进行了量化。为了减轻跨虚拟机隐秘通道的威胁,同时保持虚拟化的资源效率,提出了一种量身定制的轻量级虚拟机预配置策略,旨在确保每台服务器上的旁观者工作负载会导致隐秘通道出现足够高的错误率。通过跟踪驱动的仿真评估了所提议的VM供应策略的效率和功效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号