Agentless and Uniform Introspection for Various Security Services in IaaS Cloud

被引:2
|
作者
Zhou, Huaizhe [1 ]
Ba, Haihe [1 ]
Ren, Jiangchun [1 ]
Wang, Yongjun [1 ]
Li, Yunshi [2 ]
Chen, Yong [1 ]
Wang, Zhiying [1 ]
机构
[1] Natl Univ Def Technol, Coll Comp, Changsha 410073, Hunan, Peoples R China
[2] Chinese Acad Sci, Northwest Inst Ecoenvironm & Resources, Lanzhou 73000, Gansu, Peoples R China
基金
国家高技术研究发展计划(863计划); 中国国家自然科学基金;
关键词
cloud security; security-as-a-services; virtual machine introspection;
D O I
10.1109/ICISCE.2017.39
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the introduction of virtual machine introspection into IaaS cloud, indirect inspection of the state about guest VMs is supported with strong isolation. But it requires the privilege access to the virtual machine monitor and lacks manageability due to the need of installing various security vendors' agents in a privileged VM. In this paper, we propose an agentless and uniform introspection framework, called SE Cloud, which supports expert security vendors to build robust and flexible protections for guest VMs of their customers. With the separation of introspection and security-business code, SE Cloud can stealthily fetch the state of monitored VMs without installing any code of security vendors, which resists rootkit from compromising or evading "in-the-box" security services and is convenient to manage "out-of-the-box" security services. Our preliminary experimental results show that SE-Cloud can support robust and flexible introspection over guest VMs with acceptable overhead.
引用
收藏
页码:140 / 144
页数:5
相关论文
共 50 条
  • [1] IaaS Cloud Security
    Chavan, Pragati
    Patil, Pradeep
    Kulkarni, Gurudatt
    Sutar, Ramesh
    Belsare, Shrikant
    [J]. 2013 INTERNATIONAL CONFERENCE ON MACHINE INTELLIGENCE AND RESEARCH ADVANCEMENT (ICMIRA 2013), 2013, : 549 - 553
  • [2] A Framework Architecture for Agentless Cloud Endpoint Security Monitoring
    Ghaleb, Asem
    Traore, Issa
    Ganame, Karim
    [J]. 2019 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2019,
  • [3] CloudI: Cloud Security based on Cloud Introspection
    Zhang, Jian
    Wang, Wenxu
    Gong, Liangyi
    Gu, Zhaojun
    [J]. PROCEEDINGS OF 2018 10TH INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND COMPUTING (ICMLC 2018), 2018, : 341 - 346
  • [4] Pricing cloud IaaS computing services
    Nicola Dimitri
    [J]. Journal of Cloud Computing, 9
  • [5] Pricing cloud IaaS computing services
    Dimitri, Nicola
    [J]. JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2020, 9 (01):
  • [6] Pricing cloud IaaS computing services
    Dimitri, Nicola
    [J]. Journal of Cloud Computing, 2020, 9 (01):
  • [7] ESI-Cloud: Extending Virtual Machine Introspection for Integrating Multiple Security Services
    Ren, Jiangchun
    Liu, Ling
    Zhang, Da
    Zhou, Huaizhe
    Zhang, Qi
    [J]. PROCEEDINGS 2016 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING (SCC 2016), 2016, : 804 - 807
  • [8] Locking the sky: a survey on IaaS cloud security
    Vaquero, Luis M.
    Rodero-Merino, Luis
    Moran, Daniel
    [J]. COMPUTING, 2011, 91 (01) : 93 - 118
  • [9] Cloud Security based on IaaS Model Prospective
    Kumar, Saroj
    Singh, Priya
    Siddiqui, Shadab
    [J]. 2015 2ND INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT (INDIACOM), 2015, : 2173 - 2178
  • [10] The Role and Security of Firewalls in IaaS Cloud Computing
    Cropper, Jordan
    Ullrich, Johanna
    Fruehwirt, Peter
    Weippl, Edgar
    [J]. PROCEEDINGS 10TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY ARES 2015, 2015, : 70 - 79