Dependable and Secure Remote Management in IaaS Clouds

被引:0
|
作者
Egawa, Tomohisa [1 ]
Nishimura, Naoki [1 ]
Kourai, Kenichi [1 ]
机构
[1] Kyushu Inst Technol, Fukuoka, Japan
关键词
Virtual machine; remote management; information leakage;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In Infrastructure-as-a-Service (IaaS) clouds, the users manage the systems in the provided virtual machines (VMs) called user VMs through remote management software such as Virtual Network Computing (VNC). For dependability, they often perform out-of-band remote management via the management VM. Even in the case of system failures inside their VMs, the users could directly access their systems. However, the management VM is not always trustworthy in IaaS. Once outside or inside attackers intrude into the management VM, they could easily eavesdrop on all the inputs and outputs in remote management. To solve this security issue, this paper proposes FBCrypt for preventing information leakage via the management VM in out-of-band remote management. FBCrypt encrypts the inputs and outputs between a VNC client and a user VM using the virtual machine monitor (VMM). Sensitive information is protected against the management VM between them. The VMM intercepts the reads of virtual devices by a user VM and decrypts the inputs, whereas it intercepts the updates of a framebuffer by a user VM and encrypts the pixel data. We have implemented FBCrypt in Xen and TightVNC and confirmed that any keystrokes or pixel data did not leak.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] Secure Out-of-band Remote Management Using Encrypted Virtual Serial Consoles in IaaS Clouds
    Kourai, Kenichi
    Kajiwara, Tatsuya
    [J]. 2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 443 - 450
  • [2] Security enhancement of out-of-band remote management in IaaS clouds
    Egawa, Tomohisa
    Nishimura, Naoki
    Kourai, Kenichi
    [J]. IPSJ Online Transactions, 2013, 6 (2013) : 111 - 120
  • [3] Fault Tolerance Management in IaaS Clouds
    Jhawar, Ravi
    Piuri, Vincenzo
    [J]. 2012 IEEE FIRST AESS EUROPEAN CONFERENCE ON SATELLITE TELECOMMUNICATIONS (ESTEL), 2012,
  • [4] DEPSKY: Dependable and Secure Storage in a Cloud-of-Clouds
    Bessani, Alysson
    Correia, Miguel
    Quaresma, Bruno
    Andre, Fernando
    Sousa, Paulo
    [J]. EUROSYS 11: PROCEEDINGS OF THE EUROSYS 2011 CONFERENCE, 2011, : 31 - 45
  • [5] DEPSKY: Dependable and Secure Storage in a Cloud-of-Clouds
    Bessani, Alysson
    Correia, Miguel
    Quaresma, Bruno
    Andre, Fernando
    Sousa, Paulo
    [J]. ACM TRANSACTIONS ON STORAGE, 2013, 9 (04)
  • [6] A Proposal for Shared VMs Management in IaaS Clouds
    Makhlouf, Sid Ahmed
    Yagoubi, Belabbas
    [J]. MODELLING AND IMPLEMENTATION OF COMPLEX SYSTEMS, MISC 2016, 2016, : 201 - 215
  • [7] SLA-Aware and Green Resource Management of IaaS Clouds
    Cheng, Shuo
    Cao, Chun
    Yu, Ping
    Ma, Xiaoxing
    [J]. PROCEEDINGS OF 2016 IEEE 18TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS; IEEE 14TH INTERNATIONAL CONFERENCE ON SMART CITY; IEEE 2ND INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS), 2016, : 457 - 464
  • [8] Analytical Modeling of Reactive Autonomic Management Techniques in IaaS Clouds
    Bruneo, Dario
    Longo, Francesco
    Ghosh, Rahul
    Scarpa, Marco
    Puliafito, Antonio
    Trivedi, Kishor S.
    [J]. 2015 IEEE 8TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING, 2015, : 797 - 804
  • [9] Self-adaptive Resource Management System in IaaS Clouds
    Farahnakian, Fahimeh
    Bahsoon, Rami
    Liljeberg, Pasi
    Pahikkala, Tapio
    [J]. PROCEEDINGS OF 2016 IEEE 9TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD), 2016, : 553 - 560
  • [10] Secure Virtual Layer Management in Clouds
    Abbadi, Imad M.
    Alawneh, Muntaha
    Martin, Andrew
    [J]. TRUSTCOM 2011: 2011 INTERNATIONAL JOINT CONFERENCE OF IEEE TRUSTCOM-11/IEEE ICESS-11/FCST-11, 2011, : 99 - 110