首页> 外文期刊>International Journal of Computer Systems Science & Engineering >ICTree: Discovering the underlying connections of your rental virtual machines in the public clouds
【24h】

ICTree: Discovering the underlying connections of your rental virtual machines in the public clouds

机译:ICTree:在公共云中发现租赁虚拟机的基础连接

获取原文
获取原文并翻译 | 示例
           

摘要

Public clouds allow tenants to rent and use computing resources in terms of virtual machines (or VMs) according to wishes, however, the underlying connections among those VMs, e.g., which VMs are connected to the same switch and how the flows share the paths, are concealed for security and management considerations, yet beneficial for both malicious and non-malicious tenants. Motivated by this, this paper studies the feasibility of exploring such sensitive information from the perspective of a normal tenant. To reduce the complexity of the problem, the logical overview of the underlying connections among all the rental VMs is decomposed into multiple sub-views, namely the ICTrees, each of which illustrates the path set of incoming flows that a receiving VM would see. For practically probing such ICTrees, we introduce the loss-based two-dimension probing algorithm, where the horizontal part groups the sending VMs according to their logical ingress switches and the vertical part determines the branches that each group belongs to. We utilize only normal traffic generated by the probing VMs and need no modifications to the system software or hardware. Moreover, by leveraging the low latency feature of data center networks (or DCNs), each probing action can be accomplished in an extremely short period, e.g., 10s of milliseconds. And for a tenant with hundreds of VMs, the cumulative probe time is even less than 1 second. We thus conclude that it's possible to detect the underlying connections of the rental VMs within a very short period of time.
机译:公有云允许租户根据意愿在虚拟机(或VM)方面租用和使用计算资源,但是,这些VM之间的基础连接(例如,哪些VM连接到同一交换机以及流如何共享路径)出于安全和管理考虑而隐藏,但对恶意和非恶意租户均有利。因此,本文从普通租户的角度研究了探索此类敏感信息的可行性。为了降低问题的复杂性,将所有租用VM之间的基础连接的逻辑概述分解为多个子视图,即ICTree,每个子视图都说明了接收VM将会看到的传入流的路径集。为了实际探测此类ICTree,我们引入了基于损耗的二维探测算法,其中水平部分根据发送VM的逻辑入口开关对其进行分组,而垂直部分确定每个组所属的分支。我们仅利用由探测VM生成的正常流量,而无需修改系统软件或硬件。此外,通过利用数据中心网络(或DCN)的低延迟功能,可以在极短的时间段(例如10毫秒)内完成每个探测动作。对于拥有数百个VM的租户,累计探测时间甚至不到1秒。因此,我们得出结论,有可能在很短的时间内检测到租借VM的基础连接。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号