Dependable and Secure Remote Management in IaaS Clouds

被引:0
|
作者
Egawa, Tomohisa [1 ]
Nishimura, Naoki [1 ]
Kourai, Kenichi [1 ]
机构
[1] Kyushu Inst Technol, Fukuoka, Japan
关键词
Virtual machine; remote management; information leakage;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In Infrastructure-as-a-Service (IaaS) clouds, the users manage the systems in the provided virtual machines (VMs) called user VMs through remote management software such as Virtual Network Computing (VNC). For dependability, they often perform out-of-band remote management via the management VM. Even in the case of system failures inside their VMs, the users could directly access their systems. However, the management VM is not always trustworthy in IaaS. Once outside or inside attackers intrude into the management VM, they could easily eavesdrop on all the inputs and outputs in remote management. To solve this security issue, this paper proposes FBCrypt for preventing information leakage via the management VM in out-of-band remote management. FBCrypt encrypts the inputs and outputs between a VNC client and a user VM using the virtual machine monitor (VMM). Sensitive information is protected against the management VM between them. The VMM intercepts the reads of virtual devices by a user VM and decrypts the inputs, whereas it intercepts the updates of a framebuffer by a user VM and encrypts the pixel data. We have implemented FBCrypt in Xen and TightVNC and confirmed that any keystrokes or pixel data did not leak.
引用
收藏
页数:8
相关论文
共 50 条
  • [21] AL-SAFE: A Secure Self-Adaptable Application-Level Firewall for IaaS Clouds
    Giannakou, Anna
    Rilling, Louis
    Pazat, Jean-Louis
    Morin, Christine
    [J]. 2016 8TH IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM 2016), 2016, : 383 - 390
  • [22] A Frontier: Dependable, Reliable and Secure Machine Learning for Network/System Management
    Duc C. Le
    Nur Zincir-Heywood
    [J]. Journal of Network and Systems Management, 2020, 28 : 827 - 849
  • [23] Diagnosing Memory Provisioning in IaaS Clouds
    Pfitscher, Ricardo J.
    Pillon, Mauricio A.
    Obelheiro, Rafael R.
    [J]. 2013 III BRAZILIAN SYMPOSIUM ON COMPUTING SYSTEMS ENGINEERING (SBESC 2013), 2013, : 1 - 6
  • [24] Fogbow: a Middleware for the Federation of IaaS Clouds
    Brasileiro, Francisco
    Silva, Giovanni
    Araujo, Francisco
    Nobrega, Marcos, Jr.
    Silva, Igor
    Rocha, Gustavo
    [J]. 2016 16TH IEEE/ACM INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND GRID COMPUTING (CCGRID), 2016, : 531 - 534
  • [25] Workshop on dependable and secure nanocomputing
    Arlat, Jean
    Lyer, Ravishankar K.
    Nicolaidis, Michael
    [J]. 37TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, PROCEEDINGS, 2007, : 809 - +
  • [26] Distributed Machine Learning on IAAS Clouds
    Ta Nguyen Binh Duong
    Nguyen Quang Sang
    [J]. PROCEEDINGS OF 2018 5TH IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND INTELLIGENCE SYSTEMS (CCIS), 2018, : 58 - 62
  • [27] Continuous Disaster Tolerance in the IaaS Clouds
    Caraman, Mihai Claudiu
    Moraru, Sorin Aurel
    Dan, Stefan
    Grama, Catalin
    [J]. PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON OPTIMIZATION OF ELECTRICAL AND ELECTRONIC EQUIPMENT, VOLS 1-5, 2012, : 1226 - 1232
  • [28] Cloudburst - simulating workload for IaaS clouds
    Kross, Johannes
    Wolke, Andreas
    [J]. 2014 IEEE 7TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD), 2014, : 841 - 848
  • [29] Moving SCADA Systems to IaaS Clouds
    Church, Philip
    Mueller, Harald
    Ryan, Caspar
    Gogouvitis, Spyridon V.
    Goscinski, Andrzej
    Haitof, Houssam
    Tari, Zahir
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON SMART CITY/SOCIALCOM/SUSTAINCOM (SMARTCITY), 2015, : 908 - 914
  • [30] Dependable and secure TMO scheme
    Kim, Jungin
    Thuraisingham, Bhavani
    [J]. NINTH IEEE INTERNATIONAL SYMPOSIUM ON OBJECT AND COMPONENT-ORIENTED REAL-TIME DISTRIBUTED COMPUTING, PROCEEDINGS, 2006, : 133 - 140