CloudVMI: Virtual Machine Introspection as a Cloud Service

被引:32
作者
Baek, Hyun-wook [1 ]
Srivastava, Abhinav [2 ]
Van der Merwe, Jacobus [1 ]
机构
[1] Univ Utah, Salt Lake City, UT 84112 USA
[2] AT&T Labs Res, Florham Pk, NJ USA
来源
2014 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E) | 2014年
关键词
D O I
10.1109/IC2E.2014.82
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Virtual machine introspection (VMI) is a mechanism that allows indirect inspection and manipulation of the state of virtual machines. The indirection of this approach offers attractive isolation properties that has resulted in a variety of VMI-based applications dealing with security, performance, and debugging in virtual machine environments. Because it requires privileged access to the virtual machine monitor, VMI functionality is unfortunately not available to cloud users on public cloud platforms. In this paper, we present our work on the CloudVMI architecture to address this concern. CloudVMI virtualizes the VMI interface and makes it available as-a-service in a cloud environment. Because it allows introspection of users' VMs running on arbitrary physical machines in a cloud environment, our VMI-as-a-service abstraction allows a new class of cloud-centric VMI applications to be developed. We present the design and implementation of CloudVMI in the Xen hypervisor environment. We evaluate our implementation using a number of VMI applications, including a simple application that illustrates the cross-physical machine capabilities of CloudVMI.
引用
收藏
页码:153 / 158
页数:6
相关论文
共 20 条
[1]  
[Anonymous], 2003, NDSS
[2]  
Barham P., 2003, ACM SOSP BOLT LAND N
[3]  
Brown A., 2011, ACM CLOUD COMP SEC W
[4]  
Butt S., 2012, ACM CCS
[5]  
Dinaburg A., 2008, ACM CCS
[6]   Virtuoso: Narrowing the Semantic Gap in Virtual Machine Introspection [J].
Dolan-Gavitt, Brendan ;
Leek, Tim ;
Zhivich, Michael ;
Giffin, Jonathon ;
Lee, Wenke .
2011 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2011), 2011, :297-312
[7]  
DUNLAP G.W., 2002, OSDI
[8]  
Jiang X., 2007, ACM CCS
[9]  
Jiang X., 2007, RAID
[10]  
King S. T., 2005, USENIX ANN TECH C AN