CloudVisor: Retrofitting Protection of Virtual Machines in Multi-tenant Cloud with Nested Virtualization

被引:0
|
作者
Zhang, Fengzhe [1 ]
Chen, Jin [1 ]
Chen, Haibo [1 ]
Zang, Binyu [1 ]
机构
[1] Fudan Univ, Parallel Proc Inst, Shanghai, Peoples R China
来源
SOSP 11: PROCEEDINGS OF THE TWENTY-THIRD ACM SYMPOSIUM ON OPERATING SYSTEMS PRINCIPLES | 2011年
关键词
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Multi-tenant cloud, which usually leases resources in the form of virtual machines, has been commercially available for years. Unfortunately, with the adoption of commodity virtualized infrastructures, software stacks in typical multi-tenant clouds are non-trivially large and complex, and thus are prone to compromise or abuse from adversaries including the cloud operators, which may lead to leakage of security-sensitive data. In this paper, we propose a transparent, backward-compatible approach that protects the privacy and integrity of customers' virtual machines on commodity virtualized infrastructures, even facing a total compromise of the virtual machine monitor (VMM) and the management VM. The key of our approach is the separation of the resource management from security protection in the virtualization layer. A tiny security monitor is introduced underneath the commodity VMM using nested virtualization and provides protection to the hosted VMs. As a result, our approach allows virtualization software (e.g., VMM, management VM and tools) to handle complex tasks of managing leased VMs for the cloud, without breaking security of users' data inside the VMs. We have implemented a prototype by leveraging commercially-available hardware support for virtualization. The prototype system, called Cloud Visor, comprises only 5.5K LOCs and supports the Xen VMM with multiple Linux and Windows as the guest OSes. Performance evaluation shows that Cloud Visor incurs moderate slow-down for I/O intensive applications and very small slowdown for other applications.
引用
收藏
页码:203 / 216
页数:14
相关论文
共 50 条
  • [31] Virtualization-based techniques for enabling multi-tenant management tools
    Tsai, Chang-Hao
    Ruan, Yaoping
    Sahu, Sambit
    Shaikh, Anees
    Shin, Kang G.
    MANAGING VIRTUALIZATION OF NETWORKS AND SERVICES, PROCEEDINGS, 2007, 4785 : 171 - +
  • [32] MULTI-TENANT ACCESS CONTROL MODEL FOR CLOUD MANUFACTURING
    Chen, Qianwen
    Zhou, Zude
    Zhang, Xiaomei
    Jiang, Xuemei
    PROCEEDINGS OF THE ASME 12TH INTERNATIONAL MANUFACTURING SCIENCE AND ENGINEERING CONFERENCE - 2017, VOL 3, 2017,
  • [33] Multi-Tenant services Monitoring for Accountability in Cloud Computing
    Masmoudi, Fatma
    Loulou, Monia
    Kacem, Ahmed Hadj
    2014 IEEE 6TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), 2014, : 620 - 625
  • [34] EdgeNet: A Multi-Tenant and Multi-Provider Edge Cloud
    Senel, Berat Can
    Mouchet, Maxime
    Cappos, Justin
    Fourmaux, Olivier
    Friedman, Timur
    McGeer, Rick
    PROCEEDINGS OF THE 4TH INTERNATIONAL WORKSHOP ON EDGE SYSTEMS, ANALYTICS AND NETWORKING (EDGESYS'21), 2021, : 49 - 54
  • [35] Addressing security compatibility for multi-tenant cloud services
    Khan, Khaled M.
    Erradi, Abdelkarim
    Alhazbi, Saleh
    Han, Jun
    INTERNATIONAL JOURNAL OF COMPUTER APPLICATIONS IN TECHNOLOGY, 2013, 47 (04) : 370 - 378
  • [36] Cloud Computing Architectures Based Multi-Tenant IDS
    Khalil, Elmahdi
    Enniari, Saad
    Zbakh, Mostapha
    2013 NATIONAL SECURITY DAYS (JNS3), 2013,
  • [37] Multi-tenant Verification-as-a-Service (VaaS) in a cloud
    Hu, Kai
    Lei, Lei
    Tsai, Wei-Tek
    SIMULATION MODELLING PRACTICE AND THEORY, 2016, 60 : 122 - 143
  • [38] Deadline Guaranteed Service for Multi-Tenant Cloud Storage
    Liu, Guoxin
    Shen, Haiying
    Wang, Haoyu
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2016, 27 (10) : 2851 - 2865
  • [39] Multipath Bandwidth Guarantees for Multi-Tenant Cloud Networking
    Wang, Wei
    Sun, Yi
    Uhlig, Steve
    Fang, Gengfa
    Wang, Nanshu
    Li, Zhongcheng
    2016 IEEE 41ST CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2016, : 442 - 450
  • [40] Deadline Guaranteed Service for Multi-Tenant Cloud Storage
    Liu, Guoxin
    Shen, Haiying
    2015 IEEE INTERNATIONAL CONFERENCE ON PEER-TO-PEER COMPUTING (P2P), 2015,