An Improved Co-Resident Attack Defense Strategy Based on Multi-Level Tenant Classification in Public Cloud Platforms

被引:0
作者
Peng, Yuxi [1 ]
Jiang, Xinchen [2 ]
Wang, Shaoming [2 ]
Xiang, Yanping [2 ]
Xing, Liudong [3 ]
机构
[1] Southwest Jiaotong Univ, Sch Comp & Artificial Intelligence, Chengdu 610032, Peoples R China
[2] Univ Elect Sci & Technol China, Sch Comp Sci & Engn, Chengdu 610056, Peoples R China
[3] Univ Massachusetts, Dept Elect & Comp Engn, Dartmouth, MA 02747 USA
关键词
co-resident attack; cloud security; semi-supervised classification; SYSTEM; THEFT;
D O I
10.3390/electronics13163273
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Co-resident attacks are serious security threats in multi-tenant public cloud platforms. They are often implemented by building side channels between virtual machines (VMs) hosted on the same cloud server. Traditional defense methods are troubled by the deployment cost. The existing tenant classification methods can hardly cope with the real dataset that is quite large and extremely unevenly distributed, and may have problems in the processing speed considering the computation complexity of the DBSCAN algorithm. In this paper, we propose a novel co-resident attack defense strategy which solve these problems through an improved and efficient multi-level clustering algorithm and semi-supervised classification method. We propose a novel multi-level clustering algorithm which can efficiently reduce the complexity, since only a few parameter adjustments are required. Built on the proposed clustering algorithm, a semi-supervised classification model is designed. The experimental results of the classification effect and training speed show that our model achieves F-scores of over 85% and is significantly faster than traditional SVM classification methods. Based on the classification of unlabeled tenants into different security groups, the cloud service provider may modify the VM placement policy to achieve physical isolation among different groups, reducing the co-residency probability between attackers and target tenants. Experiments are conducted on a large-scale dataset collected from Azure Cloud Platform. The results show that the proposed model achieves 97.86% accuracy and an average 96.06% F-score, proving the effectiveness and feasibility of the proposed defense strategy.
引用
收藏
页数:18
相关论文
共 22 条
[1]   Determinating Timing Channels in Compute Clouds [J].
Aviram, Amittai ;
Hu, Sen ;
Ford, Bryan ;
Gummadi, Ramakrishna .
PROCEEDINGS OF THE 2010 ACM WORKSHOP CLOUD COMPUTING SECURITY WORKSHOP (CCSW'10:), 2010, :103-108
[2]  
Azar Yossi., 2014, Proceedings of the ACM Workshop on Cloud Computing Security, P9
[3]   On detecting co-resident cloud instances using network flow watermarking techniques [J].
Bates, Adam ;
Mood, Benjamin ;
Pletcher, Joe ;
Pruse, Hannah ;
Valafar, Masoud ;
Butler, Kevin .
INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2014, 13 (02) :171-189
[4]  
Campello Ricardo J. G. B., 2013, Advances in Knowledge Discovery and Data Mining. 17th Pacific-Asia Conference (PAKDD 2013). Proceedings, P160, DOI 10.1007/978-3-642-37456-2_14
[5]  
Hadary O, 2020, PROCEEDINGS OF THE 14TH USENIX SYMPOSIUM ON OPERATING SYSTEMS DESIGN AND IMPLEMENTATION (OSDI '20), P845
[6]   Quantify Co-Residency Risks in the Cloud Through Deep Learning [J].
Han, Jin ;
Zang, Wanyu ;
Yu, Meng ;
Sandhu, Ravi .
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2021, 18 (04) :1568-1579
[7]   A Game Theoretical Approach to Defend Against Co-Resident Attacks in Cloud Computing: Preventing Co-Residence Using Semi-Supervised Learning [J].
Han, Yi ;
Alpcan, Tansu ;
Chan, Jeffrey ;
Leckie, Christopher ;
Rubinstein, Benjamin I. P. .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2016, 11 (03) :556-570
[8]   A View Of Cloud Computing [J].
Lee, Juhnyoung .
INTERNATIONAL JOURNAL OF NETWORKED AND DISTRIBUTED COMPUTING, 2013, 1 (01) :2-8
[9]   Reliability versus Vulnerability of N-Version Programming Cloud Service Component With Dynamic Decision Time Under Co-Resident Attacks [J].
Levitin, Gregory ;
Xing, Liudong ;
Xiang, Yanping .
IEEE TRANSACTIONS ON SERVICES COMPUTING, 2022, 15 (04) :1774-1784
[10]   Co-residence based data theft game in cloud system with virtual machine replication and cancellation [J].
Levitin, Gregory ;
Xing, Liudong ;
Dai, Yuanshun .
RELIABILITY ENGINEERING & SYSTEM SAFETY, 2022, 222