Improving Security of Virtual Machines during Live Migrations

被引:0
|
作者
Biedermann, Sebastian [1 ]
Zittel, Martin [1 ]
Katzenbeisser, Stefan [1 ]
机构
[1] Tech Univ Darmstadt, Dept Comp Sci, Secur Engn Grp, Darmstadt, Germany
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Live migration of virtual machines (VMs) enables the transfer of a running VM to a new hardware component with minimal and hardly noticeable interruption. In cloud architectures, users are almost not able to detect live migrations of their VMs nor can they prevent them from happening. Nevertheless, if a VM is live migrated to a distant data center crossing national borders, security and privacy problems arise. This way, internal data can become subject to new national legislation without even notifying the owner of the live-migrated VM. In this paper, we propose methods to detect live migrations from the inside of an affected VM. Furthermore, we analyze how the live migration procedure can be delayed and how the additional gained time can be used to take security measures before the live migration is finished. We developed a "live migration defence framework" (LMDF) which can be used for security policy enforcement within a VM. We evaluated the proposed methods and techniques in our cloud setup and partially in the Amazon Elastic Computing Cloud (EC2).
引用
收藏
页码:352 / 357
页数:6
相关论文
共 50 条
  • [1] Dynamic Routing and Bandwidth Assignment for Live Virtual Machines Migrations
    Ayoub, Omran
    Pace, Luca
    Musumeci, Francesco
    Pattavina, Achille
    [J]. 20TH INTERNATIONAL CONFERENCE ON OPTICAL NETWORK DESIGN AND MODELING (ONDM 2016), 2016,
  • [2] Security-Preserving Live Migration of Virtual Machines in the Cloud
    Zhang, Fengzhe
    Chen, Haibo
    [J]. JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2013, 21 (04) : 562 - 587
  • [3] Security-Preserving Live Migration of Virtual Machines in the Cloud
    Fengzhe Zhang
    Haibo Chen
    [J]. Journal of Network and Systems Management, 2013, 21 : 562 - 587
  • [4] Virtual machines, virtual security?
    Bellovin, Steven M.
    [J]. COMMUNICATIONS OF THE ACM, 2006, 49 (10) : 104 - 104
  • [5] Estimating Energy Consumption during Live Migration of Virtual Machines
    Rybina, Kateryna
    Schill, Alexander
    [J]. 2016 IEEE INTERNATIONAL BLACK SEA CONFERENCE ON COMMUNICATIONS AND NETWORKING (BLACKSEACOM), 2016,
  • [6] Application performance Analysis during live migration of virtual machines
    Anala, M. R.
    Kashyap, Manjunath
    Shobha, G.
    [J]. PROCEEDINGS OF THE 2013 3RD IEEE INTERNATIONAL ADVANCE COMPUTING CONFERENCE (IACC), 2013, : 366 - 372
  • [7] Live migration of virtual machines
    Clark, C
    Fraser, K
    Hand, S
    Hansen, JG
    Jul, E
    Limpach, C
    Pratt, I
    Warfield, A
    [J]. USENIX ASSOCIATION PROCEEDINGS OF THE 2ND SYMPOSIUM ON NETWORKED SYSTEMS DESIGN & IMPLEMENTATION (NSDI '05), 2005, : 273 - 286
  • [8] Real security for virtual machines
    Mattsson, Ulf
    [J]. Network Security, 2009, 2009 (04) : 15 - 17
  • [9] Security Architecture for Virtual Machines
    Tupakula, Udaya
    Varadharajan, Vijay
    Bichhawat, Abhishek
    [J]. ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, PT I: ICA3PP 2011, 2011, 7916 : 218 - +
  • [10] Verification of firewall reconfiguration for virtual machines migrations in the cloud
    Jarraya, Yosr
    Eghtesadi, Arash
    Sadri, Sahba
    Debbabi, Mourad
    Pourzandi, Makan
    [J]. COMPUTER NETWORKS, 2015, 93 : 480 - 491