CloudVMI: A Cloud-Oriented Writable Virtual Machine Introspection

被引:5
|
作者
Qiang, Weizhong [1 ]
Xu, Gongping [1 ]
Dai, Weiqi [1 ]
Zou, Deqing [1 ]
Jin, Hai [1 ]
机构
[1] Huazhong Univ Sci & Technol, Big Data Technol & Syst Lab, Serv Comp Technol & Syst Lab, Cluster & Grid Comp Lab,Sch Comp Sci & Technol, Wuhan 430074, Hubei, Peoples R China
来源
IEEE ACCESS | 2017年 / 5卷
基金
中国国家自然科学基金;
关键词
Virtual machine introspection; cloud management; security monitoring;
D O I
10.1109/ACCESS.2017.2758356
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
IoT generates considerable amounts of data, which often requires leveraging cloud computing to effectively scale the costs of transferring and computing these data. The concern regarding cloud security is more severe because many devices are connected to the cloud. It is important to automatically monitor and control these resources and services to efficiently and securely deliver cloud computing. The writable virtual machine introspection (VMI) technique can not only detect the runtime state of a guest VM from the outside but also update the state from the outside without any need for administrator efforts. Thus, the writable VMI technique can provide the benefit of high automation, which is helpful for automated cloud management. However, the existing writable VMI technique produces high overhead, fails to monitor the VMs distributed on different host nodes, and fails to monitor multiple VMs with heterogeneous guest OSes within a cloud; therefore, it cannot be applied for automated and centralized cloud management. In this paper, we present CloudVMI, which is a writable and cross-node monitoring VMI framework that can overcome the aforementioned issues. CloudVMI solves the semantic gap problem by redirecting the critical execution of system calls issued by the VMI program into the monitored VM. It has strong practicability by allowing one introspection program to inspect heterogeneous guest OSes and to monitor VMs distributed on remote host nodes. Thus, CloudVMI can be directly applied for automated and centralized cloud management. Moreover, we implement some defensive measures to secure CloudVMI itself. To highlight the writable capability and practical usefulness of CloudVMI, we implement four applications based on CloudVMI. CloudVMI is designed, implemented, and systematically evaluated. The experimental results demonstrate that CloudVMI is effective and practical for cloud management and that its performance overhead is acceptable compared with existing VMI systems.
引用
收藏
页码:21962 / 21976
页数:15
相关论文
共 50 条
  • [31] Enforcing Access Controls for the Cryptographic Cloud Service Invocation Based on Virtual Machine Introspection
    Jiang, Fangjie
    Cai, Quanwei
    Guan, Le
    Lin, Jingqiang
    INFORMATION SECURITY (ISC 2018), 2018, 11060 : 213 - 230
  • [32] Virtual machine introspection - Observation or interference?
    Nance, Kara
    Hay, Brian
    Bishop, Matt
    IEEE SECURITY & PRIVACY, 2008, 6 (05) : 32 - 37
  • [33] Virtual Machine Introspection based Spurious Process Detection in Virtualized Cloud Computing Environment
    Kumara, Ajay M. A.
    Jaidhar, C. D.
    2015 1ST INTERNATIONAL CONFERENCE ON FUTURISTIC TRENDS ON COMPUTATIONAL ANALYSIS AND KNOWLEDGE MANAGEMENT (ABLAZE), 2015, : 261 - 267
  • [34] A lightweight method for virtual machine introspection
    Fursova, N. I.
    Dovgalyuk, P. M.
    Vasil'ev, I. A.
    Makarov, V. A.
    PROGRAMMING AND COMPUTER SOFTWARE, 2017, 43 (05) : 307 - 313
  • [35] Wukong: A cloud-oriented file service for mobile Internet devices
    Mao, Huajian
    Xiao, Nong
    Shi, Weisong
    Lu, Yutong
    JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2012, 72 (02) : 171 - 184
  • [36] HYBRID CLOUD-ORIENTED LEARNING ENVIRONMENT FOR IT STUDENT PROJECT TEAMWORK
    Glazunova, Olena G.
    Voloshyna, Tetyana V.
    Korolchuk, Valentyna, I
    INFORMATION TECHNOLOGIES AND LEARNING TOOLS, 2020, 77 (03) : 114 - 129
  • [37] Understanding Software Reengineering Requirements for Cloud-Oriented Service Architecture
    Zheng, Shang
    Yang, Hongji
    Zuo, Xin
    Yu, Hualong
    Shen, Jifeng
    2016 22ND INTERNATIONAL CONFERENCE ON AUTOMATION AND COMPUTING (ICAC), 2016, : 48 - 53
  • [38] A Cloud-Oriented Measurement System for Radiological Investigation and Traceability of Stones
    Donati, Massimiliano
    Marini, Marco
    Fanucci, Luca
    Fanchini, Erica
    Morichi, Massimo
    2020 IEEE INTERNATIONAL WORKSHOP ON METROLOGY FOR INDUSTRY 4.0 & IOT (METROIND4.0&IOT), 2020, : 33 - 37
  • [39] Cloud-Oriented SAT Solver Based on Obfuscating CNF Formula
    Qin, Ying
    Shen, Shengyu
    Kong, Jingzhu
    Dai, Huadong
    WEB TECHNOLOGIES AND APPLICATIONS, APWEB 2014, PT II, 2014, 8710 : 188 - 199
  • [40] Cloud-oriented emotion feedback-based Exergames framework
    Hossain, M. Shamim
    Muhammad, Ghulam
    Al-Qurishi, Muhammad
    Masud, Mehedi
    Almogren, Ahmad
    Abdul, Wadood
    Alamri, Atif
    MULTIMEDIA TOOLS AND APPLICATIONS, 2018, 77 (17) : 21861 - 21877