Security-Preserving Live Migration of Virtual Machines in the Cloud

被引:0
|
作者
Fengzhe Zhang
Haibo Chen
机构
[1] Fudan University,Parallel Processing Institute
[2] Shanghai Jiao Tong University,Institute of Parallel and Distributed Systems, School of Software
关键词
Privacy protection; Live migration; Virtual machine; Cloud;
D O I
暂无
中图分类号
学科分类号
摘要
Hypervisor-based process protection is a novel approach that provides isolated execution environments for applications running on untrusted commodity operating systems. It is based on off-the-shelf hardware and trusted hypervisors while it meets the requirement of security and trust for many cloud computing models, especially third-party data centers and a multi-tenant public cloud, in which sensitive data are out of the control of the users. However, as the hypervisor extends semantic protection to the process granularity, such a mechanism also breaks the platform independency of virtual machines and thus prohibits live migration of virtual machines, which is another highly desirable feature in the cloud. In this paper, we extend hypervisor-based process protection systems with live migration capabilities by migrating the protection-related metadata maintained in the hypervisor together with virtual machines and protecting sensitive user contents using encryption and hashing. We also propose a security-preserving live migration protocol that addresses several security threats during live migration procedures including timing-related attacks, replay attacks and resumption order attacks. We implement a prototype system base on Xen and Linux. Evaluation results show that performance degradation in terms of both total migration time and downtime are reasonably low compared to the unmodified Xen live migration system.
引用
收藏
页码:562 / 587
页数:25
相关论文
共 50 条
  • [1] Security-Preserving Live Migration of Virtual Machines in the Cloud
    Zhang, Fengzhe
    Chen, Haibo
    [J]. JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2013, 21 (04) : 562 - 587
  • [2] Live Migration of Virtual Machines in the Homogeneous Cloud
    Mohandas, Maya
    Babu, K. R. Remesh
    [J]. IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGICAL TRENDS IN COMPUTING, COMMUNICATIONS AND ELECTRICAL ENGINEERING (ICETT), 2016,
  • [3] A Strategy for Live Migration of Virtual Machines in a Cloud Federation
    Addya, Sourav Kanti
    Turuk, Ashok Kumar
    Satpathy, Anurag
    Sahoo, Bibhudatta
    Sarkar, Mahasweta
    [J]. IEEE SYSTEMS JOURNAL, 2019, 13 (03): : 2877 - 2887
  • [4] Performance of an IaaS Cloud with Live Migration of Virtual Machines
    Khazaei, Hamzeh
    Misic, Jelena
    Misic, Vojislav B.
    [J]. 2013 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2013, : 2289 - 2293
  • [5] Security-Preserving Live 3D Video Surveillance
    Tang, Zhongze
    Huy Phan
    Feng, Xianglong
    Yuan, Bo
    Liu, Yao
    Wei, Sheng
    [J]. PROCEEDINGS OF THE 2023 PROCEEDINGS OF THE 14TH ACM MULTIMEDIA SYSTEMS CONFERENCE, MMSYS 2023, 2023, : 266 - 277
  • [6] Load Balancing in Cloud Based on Live Migration of Virtual Machines
    Achar, Raghavendra
    Thilagam, P. Santhi
    Soans, Nihal
    Vikyath, P. V.
    Rao, Sathvik
    Vijeth, A. M.
    [J]. 2013 ANNUAL IEEE INDIA CONFERENCE (INDICON), 2013,
  • [7] Security analysis in the dynamic migration of virtual machines in cloud computing
    [J]. Shang, Huihua (Shanghuihua@163.com), 2017, Universidad Central de Venezuela (55):
  • [8] Live migration of virtual machines
    Clark, C
    Fraser, K
    Hand, S
    Hansen, JG
    Jul, E
    Limpach, C
    Pratt, I
    Warfield, A
    [J]. USENIX ASSOCIATION PROCEEDINGS OF THE 2ND SYMPOSIUM ON NETWORKED SYSTEMS DESIGN & IMPLEMENTATION (NSDI '05), 2005, : 273 - 286
  • [9] Krill Herd Algorithm for Live Virtual Machines Migration in Cloud Environments
    Cao, Hui
    Hou, Zhuo
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (05) : 718 - 724
  • [10] Clique Migration: Affinity Grouping of Virtual Machines for Inter-Cloud Live Migration
    Lu, Tao
    Stuart, Morgan
    Tang, Kun
    He, Xubin
    [J]. 2014 9TH IEEE INTERNATIONAL CONFERENCE ON NETWORKING, ARCHITECTURE, AND STORAGE (NAS), 2014, : 216 - 225