CloudVMI: A Cloud-Oriented Writable Virtual Machine Introspection

被引:5
|
作者
Qiang, Weizhong [1 ]
Xu, Gongping [1 ]
Dai, Weiqi [1 ]
Zou, Deqing [1 ]
Jin, Hai [1 ]
机构
[1] Huazhong Univ Sci & Technol, Big Data Technol & Syst Lab, Serv Comp Technol & Syst Lab, Cluster & Grid Comp Lab,Sch Comp Sci & Technol, Wuhan 430074, Hubei, Peoples R China
来源
IEEE ACCESS | 2017年 / 5卷
基金
中国国家自然科学基金;
关键词
Virtual machine introspection; cloud management; security monitoring;
D O I
10.1109/ACCESS.2017.2758356
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
IoT generates considerable amounts of data, which often requires leveraging cloud computing to effectively scale the costs of transferring and computing these data. The concern regarding cloud security is more severe because many devices are connected to the cloud. It is important to automatically monitor and control these resources and services to efficiently and securely deliver cloud computing. The writable virtual machine introspection (VMI) technique can not only detect the runtime state of a guest VM from the outside but also update the state from the outside without any need for administrator efforts. Thus, the writable VMI technique can provide the benefit of high automation, which is helpful for automated cloud management. However, the existing writable VMI technique produces high overhead, fails to monitor the VMs distributed on different host nodes, and fails to monitor multiple VMs with heterogeneous guest OSes within a cloud; therefore, it cannot be applied for automated and centralized cloud management. In this paper, we present CloudVMI, which is a writable and cross-node monitoring VMI framework that can overcome the aforementioned issues. CloudVMI solves the semantic gap problem by redirecting the critical execution of system calls issued by the VMI program into the monitored VM. It has strong practicability by allowing one introspection program to inspect heterogeneous guest OSes and to monitor VMs distributed on remote host nodes. Thus, CloudVMI can be directly applied for automated and centralized cloud management. Moreover, we implement some defensive measures to secure CloudVMI itself. To highlight the writable capability and practical usefulness of CloudVMI, we implement four applications based on CloudVMI. CloudVMI is designed, implemented, and systematically evaluated. The experimental results demonstrate that CloudVMI is effective and practical for cloud management and that its performance overhead is acceptable compared with existing VMI systems.
引用
收藏
页码:21962 / 21976
页数:15
相关论文
共 50 条
  • [1] CloudVMI: Virtual Machine Introspection as a Cloud Service
    Baek, Hyun-wook
    Srivastava, Abhinav
    Van der Merwe, Jacobus
    [J]. 2014 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E), 2014, : 153 - 158
  • [2] Cloud-Oriented Virtual Machine Management with MLN
    Begnum, Kyrre
    Lartey, Nil Apleh
    Xing, Lu
    [J]. CLOUD COMPUTING, PROCEEDINGS, 2009, 5931 : 266 - 277
  • [3] Simplified cloud-oriented virtual machine management with MLN
    Begnum, Kyrre
    [J]. JOURNAL OF SUPERCOMPUTING, 2012, 61 (02): : 251 - 266
  • [4] CloudController: A Writable and Heterogeneous-Adaptive Virtual Machine Introspection for Cloud Management
    Qiang, Weizhong
    Xu, Gongping
    Sun, Guozhong
    Zhu, Tianqing
    Jin, Hai
    [J]. 2017 16TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS / 11TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING / 14TH IEEE INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS, 2017, : 177 - 184
  • [5] Simplified cloud-oriented virtual machine management with MLN
    Kyrre Begnum
    [J]. The Journal of Supercomputing, 2012, 61 : 251 - 266
  • [6] CryptVMI: Encrypted Virtual Machine Introspection in the Cloud
    Yao, Fangzhou
    Campbell, Roy H.
    [J]. 2014 IEEE 7TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD), 2014, : 977 - 978
  • [7] Virtual Machine Introspection based Cloud Monitoring Platform
    Lauren, Samuel
    Leppanen, Ville
    [J]. COMPUTER SYSTEMS AND TECHNOLOGIES (COMPSYSTECH'18), 2018, 1641 : 104 - 109
  • [8] A Cloud-oriented Algorithm for Virtual Network Embedding Over Multi-Domain
    Li, Shuopeng
    Saidi, Mohand Yazid
    Chen, Ken
    [J]. PROCEEDINGS OF THE 2016 IEEE 41ST CONFERENCE ON LOCAL COMPUTER NETWORKS - LCN WORKSHOPS 2016, 2016, : 50 - 57
  • [9] Cloud Computing: Several Cloud-oriented Solutions
    Haji, Amel
    Ben Letaifa, Asma
    Tabbane, Sami
    [J]. PROCEEDINGS OF THE FOURTH INTERNATIONAL CONFERENCE ON ADVANCED ENGINEERING COMPUTING AND APPLICATIONS IN SCIENCES (ADVCOMP 2010), 2010, : 137 - 141
  • [10] Towards virtual machine introspection based security framework for cloud
    Borisaniya, Bhavesh
    Patel, Dhiren
    [J]. SADHANA-ACADEMY PROCEEDINGS IN ENGINEERING SCIENCES, 2019, 44 (02):