Cache Covert-Channel Mitigation in Cloud Virtualization with XEN's Credit Scheduler

被引:0
|
作者
Zeiser, Maximilian [1 ]
Betz, Johann [1 ]
Westhoff, Dirk [1 ]
机构
[1] Hsch Offenburg Univ, Offenburg, Germany
关键词
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Covert- and side-channels as well as techniques to establish them in cloud computing are in focus of research for quite some time. However, not many concrete mitigation methods have been developed and even less have been adapted and concretely implemented by cloud providers. Thus, we recently conceptually proposed C-3-Sched a CPU scheduling based approach to mitigate L2 cache covert-channels. Instead offlushing the cache on every context switch, we schedule trusted virtual machines to create noise which prevents potential covert-channels. Additionally, our approach aims on preserving performance by utilizing existing instead of artificial workload while reducing covert-channel related cache flushes to cases where not enough noise has been achieved. In this work we evaluate cache covert-channel mitigation and performance impact of our integration of C-3-Sched in the XEN credit scheduler. Moreover, we compare it to naive solutions and more competitive approaches.
引用
收藏
页数:7
相关论文
共 2 条
  • [1] C3-Sched - A Cache Covert Channel robust Cloud Computing Scheduler
    Betz, Johann
    Westhoff, Dirk
    [J]. 2014 9TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2014, : 54 - 60
  • [2] Streamline: A Fast, Flushless Cache Covert-Channel Attack by Enabling Asynchronous Collusion
    Saileshwar, Gururaj
    Fletcher, Christopher W.
    Qureshi, Moinuddin
    [J]. ASPLOS XXVI: TWENTY-SIXTH INTERNATIONAL CONFERENCE ON ARCHITECTURAL SUPPORT FOR PROGRAMMING LANGUAGES AND OPERATING SYSTEMS, 2021, : 1077 - 1090