Secure Partitioning of Cloud Applications, with Cost Look-Ahead

被引:0
|
作者
Bocci, Alessandro [1 ]
Forti, Stefano [1 ]
Guanciale, Roberto [2 ]
Ferrari, Gian-Luigi [1 ]
Brogi, Antonio [1 ]
机构
[1] Univ Pisa, Dept Comp Sci, I-56127 Pisa, Italy
[2] KTH Royal Inst Technol, Div Theoret Comp Sci, S-11428 Stockholm, Sweden
关键词
data confidentiality; trusted execution environments; separation kernels; information-flow security; deployment costs; declarative programming; ISSUES;
D O I
10.3390/fi15070224
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The security of Cloud applications is a major concern for application developers and operators. Protecting users' data confidentiality requires methods to avoid leakage from vulnerable software and unreliable Cloud providers. Recently, trusted execution environments (TEEs) emerged in Cloud settings to isolate applications from the privileged access of Cloud providers. Such hardware-based technologies exploit separation kernels, which aim at safely isolating the software components of applications. In this article, we propose a methodology to determine safe partitionings of Cloud applications to be deployed on TEEs. Through a probabilistic cost model, we enable application operators to select the best trade-off partitioning in terms of future re-partitioning costs and the number of domains. To the best of our knowledge, no previous proposal exists addressing such a problem. We exploit information-flow security techniques to protect the data confidentiality of applications by relying on declarative methods to model applications and their data flow. The proposed solution is assessed by executing a proof-of-concept implementation that shows the relationship among the future partitioning costs, number of domains and execution times.
引用
收藏
页数:38
相关论文
共 50 条
  • [21] Online optimization with gradual look-ahead
    Dunke, Fabian
    Nickel, Stefan
    OPERATIONAL RESEARCH, 2021, 21 (04) : 2489 - 2523
  • [22] INFINITESIMAL LOOK-AHEAD STOPPING RULES
    ROSS, SM
    ANNALS OF MATHEMATICAL STATISTICS, 1971, 42 (01): : 297 - &
  • [23] ON THE LOOK-AHEAD PROBLEM IN LEXICAL ANALYSIS
    YANG, W
    ACTA INFORMATICA, 1995, 32 (05) : 459 - 476
  • [24] Look-Ahead: X MARKS THE SPOT
    Chicago, United States
    Cutting Tool Eng, 2020, 3 (56):
  • [25] A Look-Ahead B&B Search for Cost-Based Planning
    Fuentetaja, Raquel
    Borrajo, Daniel
    Linares Lopez, Carlos
    CURRENT TOPICS IN ARTIFICIAL INTELLIGENCE, 2010, 5988 : 201 - 211
  • [26] Optimized look-ahead tree policies: a bridge between look-ahead tree policies and direct policy search
    Jung, Tobias
    Wehenkel, Louis
    Ernst, Damien
    Maes, Francis
    INTERNATIONAL JOURNAL OF ADAPTIVE CONTROL AND SIGNAL PROCESSING, 2014, 28 (3-5) : 255 - 289
  • [27] Efficient language model look-ahead probabilities generation using lower order LM look-ahead information
    Chen, Langzhou
    Chin, K. K.
    2008 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING, VOLS 1-12, 2008, : 4925 - 4928
  • [28] Optimizing the makespan and reliability for workflow applications with reputation and a look-ahead genetic algorithm
    Wang, Xiaofeng
    Yeo, Chee Shin
    Buyya, Rajkumar
    Su, Jinshu
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2011, 27 (08): : 1124 - 1134
  • [29] Mesh stability of look-ahead interconnected systems
    Pant, A
    Seiler, P
    Hedrick, K
    IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2002, 47 (02) : 403 - 407
  • [30] Tissue P Systems with Look-ahead Mode
    JIANG Yun
    SONG Tao
    ZHANG Zheng
    ChineseJournalofElectronics, 2014, 23 (01) : 81 - 86