Secure virtual machine placement in cloud data centers

被引:24
|
作者
Agarwal, Amit [1 ]
Ta Nguyen Binh Duong [2 ]
机构
[1] BITS Pilani, Pilani, Goa, India
[2] Nanyang Technol Univ, SCSE, Singapore, Singapore
关键词
Data centers; Cloud security; Co-location attacks; Virtual machine placement; MANAGEMENT;
D O I
10.1016/j.future.2019.05.005
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Due to an increasing number of avenues for conducting cross-VM side-channel attacks, the security of multi-tenant public IaaS cloud environments is a growing concern. These attacks allow an adversary to steal private information from a target user whose VM instance is co-located with that of the adversary. In this paper, we focus on secure VM placement algorithms which a cloud provider can use for the automatic enforcement of security against such co-location based attacks. To do so, we first establish a metric for evaluating and quantifying co-location security of multi-tenant public IaaS clouds, and then propose a novel VM placement algorithm called "Previously Co-Located Users First" which aims to reduce the probability of malicious VM co-location. Thereafter, we perform a theoretical and empirical analysis of our proposed algorithm to evaluate its efficiency and security. Our results, obtained using real-world cloud traces containing millions of VM requests and thousands of actual users, indicate that the proposed algorithm provides a significant increase in the cloud's co-location resistance with little compromise in resource utilization, compared to existing approaches. We also explore the potential for cloud providers to leverage passive cache monitoring techniques as an additional security measure in order to automatically improve the co-location resistance provided by general VM placement algorithms. (C) 2019 Elsevier B.V. All rights reserved.
引用
收藏
页码:210 / 222
页数:13
相关论文
共 50 条
  • [1] An Approach to Virtual Machine Placement in Cloud Data Centers
    Telenyk, Sergii
    Zharikov, Eduard
    Rolik, Oleksandr
    [J]. 2016 INTERNATIONAL CONFERENCE RADIO ELECTRONICS & INFO COMMUNICATIONS (UKRMICO), 2016,
  • [2] An approximation algorithm for virtual machine placement in cloud data centers
    Zahra Mahmoodabadi
    Mostafa Nouri-Baygi
    [J]. The Journal of Supercomputing, 2024, 80 : 915 - 941
  • [3] Multicriteria Optimization of Virtual Machine Placement in Cloud Data Centers
    Toutov, Andrew
    Toutova, Natalia
    Vorozhtsov, Anatoly
    Andreev, Ilya
    [J]. PROCEEDINGS OF THE 28TH CONFERENCE OF OPEN INNOVATIONS ASSOCIATION FRUCT, 2021, : 482 - 487
  • [4] An approximation algorithm for virtual machine placement in cloud data centers
    Mahmoodabadi, Zahra
    Nouri-Baygi, Mostafa
    [J]. JOURNAL OF SUPERCOMPUTING, 2024, 80 (01): : 915 - 941
  • [5] Flow and Virtual Machine Placement in Wireless Cloud Data Centers
    Roh, Heejun
    Kim, Kyunghwi
    Pack, Sangheon
    Lee, Wonjun
    [J]. QUALITY, RELIABILITY, SECURITY AND ROBUSTNESS IN HETEROGENEOUS NETWORKS, 2017, 199 : 138 - 148
  • [6] Big Data Aware Virtual Machine Placement in Cloud Data Centers
    Hall, Logan
    Harris, Bryan
    Tomes, Erica
    Altiparmak, Nihat
    [J]. BDCAT'17: PROCEEDINGS OF THE FOURTH IEEE/ACM INTERNATIONAL CONFERENCE ON BIG DATA COMPUTING, APPLICATIONS AND TECHNOLOGIES, 2017, : 209 - 218
  • [7] A Secure and Multiobjective Virtual Machine Placement Framework for Cloud Data Center
    Saxena, Deepika
    Gupta, Ishu
    Kumar, Jitendra
    Singh, Ashutosh Kumar
    Wen, Xiaoqing
    [J]. IEEE SYSTEMS JOURNAL, 2022, 16 (02): : 3163 - 3174
  • [8] Migration-Aware Virtual Machine Placement for Cloud Data Centers
    Wang, Xiumin
    Yuen, Chau
    Ul Hassan, Naveed
    Wang, Wei
    Chen, Tian
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATION WORKSHOP (ICCW), 2015, : 1940 - 1945
  • [9] Energy-Saving Virtual Machine Placement in Cloud Data Centers
    Dong, Jiankang
    Jin, Xing
    Wang, Hongbo
    Li, Yangyang
    Zhang, Peng
    Cheng, Shiduan
    [J]. PROCEEDINGS OF THE 2013 13TH IEEE/ACM INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND GRID COMPUTING (CCGRID 2013), 2013, : 618 - 624
  • [10] Joint flow and virtual machine placement in hybrid cloud data centers
    Roh, Heejun
    Jung, Cheoulhoon
    Kim, Kyunghwi
    Pack, Sangheon
    Lee, Wonjun
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2017, 85 : 4 - 13