CloudVisor: Retrofitting Protection of Virtual Machines in Multi-tenant Cloud with Nested Virtualization

被引:0
|
作者
Zhang, Fengzhe [1 ]
Chen, Jin [1 ]
Chen, Haibo [1 ]
Zang, Binyu [1 ]
机构
[1] Fudan Univ, Parallel Proc Inst, Shanghai, Peoples R China
关键词
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Multi-tenant cloud, which usually leases resources in the form of virtual machines, has been commercially available for years. Unfortunately, with the adoption of commodity virtualized infrastructures, software stacks in typical multi-tenant clouds are non-trivially large and complex, and thus are prone to compromise or abuse from adversaries including the cloud operators, which may lead to leakage of security-sensitive data. In this paper, we propose a transparent, backward-compatible approach that protects the privacy and integrity of customers' virtual machines on commodity virtualized infrastructures, even facing a total compromise of the virtual machine monitor (VMM) and the management VM. The key of our approach is the separation of the resource management from security protection in the virtualization layer. A tiny security monitor is introduced underneath the commodity VMM using nested virtualization and provides protection to the hosted VMs. As a result, our approach allows virtualization software (e.g., VMM, management VM and tools) to handle complex tasks of managing leased VMs for the cloud, without breaking security of users' data inside the VMs. We have implemented a prototype by leveraging commercially-available hardware support for virtualization. The prototype system, called Cloud Visor, comprises only 5.5K LOCs and supports the Xen VMM with multiple Linux and Windows as the guest OSes. Performance evaluation shows that Cloud Visor incurs moderate slow-down for I/O intensive applications and very small slowdown for other applications.
引用
收藏
页码:203 / 216
页数:14
相关论文
共 50 条
  • [1] Security Assessment Framework for Multi-tenant Cloud with Nested Virtualization
    Mjihil, Oussama
    Kim, Dong Seong
    Haqiq, Abdelkrim
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2016, 11 (02): : 87 - 96
  • [2] Security Assessment Framework for Multi-tenant Cloud with Nested Virtualization
    Mjihil, Oussama
    Kim, Dong Seong
    Haqiq, Abdelkrim
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2016, 11 (05): : 283 - 292
  • [3] Towards Multi-Tenant and Interoperable Monitoring of Virtual Machines in Cloud
    Tovarnak, Daniel
    Pitner, Tomas
    14TH INTERNATIONAL SYMPOSIUM ON SYMBOLIC AND NUMERIC ALGORITHMS FOR SCIENTIFIC COMPUTING (SYNASC 2012), 2012, : 436 - 442
  • [4] Network Function Virtualization in the Multi-Tenant Cloud
    Yu, Ruozhou
    Xue, Guoliang
    Kilari, Vishnu Teja
    Zhang, Xiang
    IEEE NETWORK, 2015, 29 (03): : 42 - 47
  • [5] RAS: Reliable Auto-Scaling of Virtual Machines in Multi-Tenant Cloud Networks
    Ayoubi, Sara
    Zhang, Yanhong
    Assi, Chadi
    2015 IEEE 4TH INTERNATIONAL CONFERENCE ON CLOUD NETWORKING (CLOUDNET), 2015, : 1 - 6
  • [6] Optimal Virtual Machine Placement in a Multi-tenant Cloud
    Teyeb, Hana
    Balma, Ali
    Ben Hadj-Alouane, Nejib
    Tata, Samir
    SERVICE-ORIENTED COMPUTING - ICSOC 2014 WORKSHOPS, 2015, 8954 : 308 - 319
  • [7] SVirt: A Substrate-agnostic SDN Virtualization Architecture for Multi-tenant Cloud
    Yu, Yirong
    Li, Dan
    Huang, Yukai
    2015 IEEE 23RD INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2015, : 313 - 322
  • [8] Multi-Tenant Programmable Switch Virtualization Architecture
    Lamb, Ivan Peter
    Facen, Theo
    Duarte, Pedro
    Azambuja, Jose Rodrigo
    Cordeiro, Weverton
    PROCEEDINGS OF 2024 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, NOMS 2024, 2024,
  • [9] Multi-tenant SaaS Cloud
    Kulkarni, Gurudatt
    Khatawkar, Prasad
    Shelke, Rupali
    Solanke, Vikas
    Waghmare, Rani
    AFRICON, 2013, 2013,
  • [10] Multi-tenant SaaS Cloud
    Kulkarni, Gurudatt
    Shelke, Rupali
    Palwe, Rajnikant
    Khatawkar, Prasad
    Bhuse, Sadanand
    Bankar, Hemant
    2013 FOURTH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATIONS AND NETWORKING TECHNOLOGIES (ICCCNT), 2013,