Uncovering the Security Implications of Cloud Multi-Tenancy with Bolt

被引:0
|
作者
Delimitrou, Christina [1 ,2 ]
Kozyrakis, Christos [3 ,4 ]
机构
[1] Cornell Univ, Dept Elect & Comp Engn, Ithaca, NY 14853 USA
[2] Cornell Univ, Dept Comp Sci, Ithaca, NY 14853 USA
[3] Stanford Univ, Dept Elect Engn, Stanford, CA 94305 USA
[4] Stanford Univ, Dept Comp Sci, Stanford, CA 94305 USA
关键词
cloud computing; denial of service; hardware; isolation; partitioning; quality of service; security;
D O I
10.1109/MM.2018.032271065
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud providers routinely schedule multiple applications per physical host to increase efficiency. The resulting interference on shared resources often leads to performance degradation and, more importantly, security vulnerabilities. Interference can leak important information about an application, ranging from a service's placement to confidential data, such as private keys. We present Bolt, a practical system that accurately detects the type and characteristics of applications sharing a cloud platform based on the interference an adversary sees on shared resources. Bolt leverages online data mining techniques that only require 2-5 seconds for detection. In a multi-user study on Amazon Elastic Compute Cloud (EC2), Bolt correctly identifies the characteristics of 385 out of a set of 436 diverse workloads. Extracting this information enables a wide spectrum of previously impractical cloud attacks, including denial of service (DoS) attacks that increase tail latency by 140X, as well as resource freeing attacks (RFAs), and co-residency attacks. Finally, we show that, while advanced isolation mechanisms such as cache partitioning lower detection accuracy, they are insufficient to eliminate these vulnerabilities altogether. To do so, one must either disallow core sharing or allow it only between threads of the same application, leading to significant inefficiencies and performance penalties.
引用
收藏
页码:86 / 97
页数:12
相关论文
共 50 条
  • [1] Security in Multi-Tenancy Cloud
    Jasti, Amarnath
    Shah, Payal
    Nagaraj, Rajeev
    Pendse, Ravi
    [J]. 44TH ANNUAL 2010 IEEE INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY, 2010, : 35 - 41
  • [2] Multi-Tenancy in Cloud Computing
    AlJahdali, Hussain
    Albatli, Abdulaziz
    Garraghan, Peter
    Townend, Paul
    Lau, Lydia
    Xu, Jie
    [J]. 2014 IEEE 8TH INTERNATIONAL SYMPOSIUM ON SERVICE ORIENTED SYSTEM ENGINEERING (SOSE), 2014, : 344 - 351
  • [3] Multi-Tenancy Cloud-Enabled Small Cell Security
    Abubakar, Babangida Albaba
    Mouratidis, Haralambos
    [J]. 2019 2ND INTERNATIONAL CONFERENCE OF THE IEEE NIGERIA COMPUTER CHAPTER (NIGERIACOMPUTCONF), 2019, : 257 - 262
  • [4] Cloud Multi-Tenancy: Issues and Developments
    Odun-Ayo, Isaac
    Misra, Sanjay
    Abayomi-Alli, Olusola
    Ajayi, Olasupo
    [J]. COMPANION PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON UTILITY AND CLOUD COMPUTING (UCC'17 COMPANION), 2017, : 209 - 214
  • [5] Enhancing Multi-Tenancy Security in the Cloud IaaS Model over Public Deployment
    AlJahdali, Hussain
    Townend, Paul
    Xu, Jie
    [J]. 2013 IEEE SEVENTH INTERNATIONAL SYMPOSIUM ON SERVICE-ORIENTED SYSTEM ENGINEERING (SOSE 2013), 2013, : 385 - 390
  • [6] AN AUTHORIZATION MODEL FOR MULTI-TENANCY SERVICES IN CLOUD
    Zhang, Zhaohai
    Wen, Qiaoyan
    [J]. 2012 IEEE 2nd International Conference on Cloud Computing and Intelligent Systems (CCIS) Vols 1-3, 2012, : 260 - 263
  • [7] Multi-tenancy Authorization System in Multi Cloud Services
    Rao, M. Varaprasad
    Murthy, G. Vishnu
    Kumar, V. Vijaya
    [J]. PROCEEDINGS OF THE 2017 INTERNATIONAL CONFERENCE ON BIG DATA ANALYTICS AND COMPUTATIONAL INTELLIGENCE (ICBDAC), 2017, : 408 - 411
  • [8] Architecture Support for FPGA Multi-tenancy in the Cloud
    Mbongue, Joel Mandebi
    Shuping, Alex
    Bhowmik, Pankaj
    Bobda, Christophe
    [J]. 2020 IEEE 31ST INTERNATIONAL CONFERENCE ON APPLICATION-SPECIFIC SYSTEMS, ARCHITECTURES AND PROCESSORS (ASAP 2020), 2020, : 125 - 132
  • [9] MULTI-TENANCY IN BUSINESS SUPPORT SYSTEMS CLOUD DEPLOYMENTS
    Dragan, Ioan
    Zota, Razvan Daniel
    [J]. INTERNATIONAL CONFERENCE ON INFORMATICS IN ECONOMY, IE 2016: EDUCATION, RESEARCH & BUSINESS TECHNOLOGIES, 2016, : 32 - 37
  • [10] Multi-tenancy access control strategy for cloud services
    Zou, Maoyang
    He, Jia
    Wu, Qian
    [J]. PROCEEDINGS OF 2016 10TH INTERNATIONAL CONFERENCE ON SOFTWARE, KNOWLEDGE, INFORMATION MANAGEMENT & APPLICATIONS (SKIMA), 2016, : 258 - 261