首页> 外文期刊>Journal of network and systems management >Security-Preserving Live Migration of Virtual Machines in the Cloud
【24h】

Security-Preserving Live Migration of Virtual Machines in the Cloud

机译:云中虚拟机的安全保全实时迁移

获取原文
获取原文并翻译 | 示例
           

摘要

Hypervisor-based process protection is a novel approach that provides isolated execution environments for applications running on untrusted commodity operating systems. It is based on off-the-shelf hardware and trusted hypervisors while it meets the requirement of security and trust for many cloud computing models, especially third-party data centers and a multi-tenant public cloud, in which sensitive data are out of the control of the users. However, as the hypervisor extends semantic protection to the process granularity, such a mechanism also breaks the platform independency of virtual machines and thus prohibits live migration of virtual machines, which is another highly desirable feature in the cloud. In this paper, we extend hypervisor-based process protection systems with live migration capabilities by migrating the protection-related metadata maintained in the hypervisor together with virtual machines and protecting sensitive user contents using encryption and hashing. We also propose a security-preserving live migration protocol that addresses several security threats during live migration procedures including timing-related attacks, replay attacks and resumption order attacks. We implement a prototype system base on Xen and Linux. Evaluation results show that performance degradation in terms of both total migration time and downtime are reasonably low compared to the unmodified Xen live migration system.
机译:基于虚拟机监控程序的进程保护是一种新颖的方法,可以为在不受信任的商品操作系统上运行的应用程序提供隔离的执行环境。它基于现成的硬件和受信任的虚拟机管理程序,同时满足许多云计算模型(尤其是第三方数据中心和多租户公共云)的安全性和信任要求,其中敏感数据不在其中。控制用户。但是,随着虚拟机管理程序将语义保护扩展到进程粒度,这种机制也破坏了虚拟机的平台独立性,因此禁止了虚拟机的实时迁移,这是云中另一个非常受欢迎的功能。在本文中,我们通过将虚拟机管理程序中维护的与保护相关的元数据与虚拟机一起迁移,并使用加密和哈希保护敏感的用户内容,来扩展具有实时迁移功能的基于虚拟机管理程序的流程保护系统。我们还提出了一种保留安全性的实时迁移协议,该协议可解决实时迁移过程中的几种安全威胁,包括与时序有关的攻击,重播攻击和恢复命令攻击。我们在Xen和Linux上实现原型系统。评估结果表明,与未修改的Xen live迁移系统相比,在总迁移时间和停机时间方面的性能下降都相当低。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号