When Dynamic VM Migration Falls Under the Control of VM Users

被引:8
|
作者
Lazri, Kahina [1 ,2 ]
Laniepce, Sylvie [1 ]
Ben-Othman, Jalel [2 ]
机构
[1] Orange Labs, Secur Dept, Caen, France
[2] Univ Paris 13, Lab L2TI, F-93430 Villetaneuse, France
来源
2013 IEEE FIFTH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), VOL 1 | 2013年
关键词
Cloud Computing; Security; VM Migration; Multi-tenancy; Isolation; Vulnerability;
D O I
10.1109/CloudCom.2013.58
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security of multi-tenancy in cloud platforms raises a growing interest since research has revealed that the sharing of resources constitutes a vector of vulnerability. In this paper, we examine how one can leverage the sharing of resources, through the manipulation of the amount of resources consumed by VMs, to abusively enforce the dynamic resource management system to trigger VM migrations. This causes waste of resources for the hosting infrastructure and affects performances of VMs. To demonstrate this cross-VM attack, we use VMware's Distributed Resource Scheduler (DRS) in charge of dynamic VM migration management. We perform a detailed analysis of the running of our experimentations by monitoring DRS details during the whole duration of the attack. We explore in various contexts the minimum amount of resources required for the attack to succeed. In our experimentation performed on small clusters, we observe higher vulnerability when the cluster gets larger and when DRS aggressiveness level gets higher. Finally, our experimentations show that the attack can be replayed several times to produce series of VM migrations.
引用
收藏
页码:395 / 402
页数:8
相关论文
共 50 条
  • [21] A Versioning Approach to VM Live Migration
    Tajamolian, M.
    Ghasemzadeh, M.
    INTERNATIONAL JOURNAL OF ENGINEERING, 2018, 31 (11): : 1838 - 1845
  • [22] VM Migration Measurement and Failure Detection
    Kukral, Tomas
    Kozak, Milca
    Hegr, Tomas
    Bohac, Leos
    2015 38TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS AND SIGNAL PROCESSING (TSP), 2015, : 285 - 288
  • [23] Evaluation of Cluster K-Means as VM Selection in Dynamic VM Consolidation
    Shidik, Guruh Fajar
    Sulistyowati, Nani Sri
    Tirta, Manggiardi B. W.
    2016 22ND ASIA-PACIFIC CONFERENCE ON COMMUNICATIONS (APCC), 2016, : 124 - 128
  • [24] VM consolidation approach based on heuristics fuzzy logic, and migration control
    Monil, Mohammad Alaul Haque
    Rahman, Rashedur M.
    JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2016, 5
  • [25] VM consolidation approach based on heuristics, fuzzy logic, and migration control
    Mohammad Alaul Haque Monil
    Rashedur M. Rahman
    Journal of Cloud Computing, 5
  • [26] VM & process control system
    Zhang, YK
    Wang, WH
    Sun, YX
    1997 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENT PROCESSING SYSTEMS, VOLS 1 & 2, 1997, : 801 - 804
  • [27] Online Scheduling for Dynamic VM Migration in Multicast Time-Sensitive Networks
    Yu, Qinghan
    Wan, Hai
    Zhao, Xibin
    Gao, Yue
    Gu, Ming
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2020, 16 (06) : 3778 - 3788
  • [28] Dynamic VM allocation in a SaaS environment
    Brian Bouterse
    Harry Perros
    Annals of Telecommunications, 2018, 73 : 205 - 218
  • [29] A Distributed Approach to Dynamic VM Management
    Tighe, Michael
    Keller, Gaston
    Bauer, Michael
    Lutfiyya, Hanan
    2013 9TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2013, : 166 - 170
  • [30] Dynamic VM allocation in a SaaS environment
    Bouterse, Brian
    Perros, Harry
    ANNALS OF TELECOMMUNICATIONS, 2018, 73 (3-4) : 205 - 218