...
首页> 外文期刊>Progress in Artificial Intelligence >Secure VM management with strong user binding in semi-trusted clouds
【24h】

Secure VM management with strong user binding in semi-trusted clouds

机译:使用SEMI-Trusted Clouds中的强大用户绑定安全VM管理

获取原文
获取原文并翻译 | 示例

摘要

In Infrastructure-as-a-Service (IaaS) clouds, remote users access provided virtual machines (VMs) via the management server. The management server is managed by cloud operators, but not all the cloud operators are trusted in semi-trusted clouds. They can execute arbitrary management commands to users' VMs and redirect users' commands to malicious VMs. We call the latter attack the VM redirection attack. The root cause is that the binding of remote users to their VMs is weak. In other words, it is difficult to enforce the execution of only users' management commands to their VMs. In this paper, we propose UVBond for strongly binding users to their VMs to address this issue. UVBond boots user's VM by decrypting its encrypted disk inside the trusted hypervisor. Then it issues a VM descriptor to securely identify that VM. To bridge the semantic gap between high-level management commands and low-level hypercalls, UVBond uses hypercall automata, which accept the sequences of hypercalls issued by commands. We have implemented UVBond in Xen and created hypercall automata for various management commands. Using UVBond, we confirmed that a VM descriptor and hypercall automata prevented insider attacks and that the overhead was not large in remote VM management.
机译:在基础架构 - AS-AS-Service(IAAS)云中,远程用户通过管理服务器访问虚拟机(VM)。管理服务器由云运算符管理,但并非所有云运算符都在半信制的云中受到信任。它们可以对用户的VMS执行任意管理命令并将用户的命令重定向到恶意VM。我们称之为攻击VM重定向攻击。根本原因是远程用户对其VM的绑定很弱。换句话说,很难强制执行用户的管理命令对其VM的执行。在本文中,我们向VM提出了强烈绑定用户的UVBond,以解决这个问题。 UVBond启动用户的VM通过解密可信管理程序内的加密磁盘。然后它发出VM描述符以安全地标识该VM。为了弥合高级管理命令和低级超级功能之间的语义差距,UVBOND使用HyperCall自动机,接受命令颁发的HyperCalls序列。我们在Xen实现了UVBond,并为各种管理命令创建了HyperCall Automata。使用UVBond,我们确认了VM描述符和HyperCall Automata阻止了内部攻击,并且远程VM管理中的开销不大。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号