CloudVisor: Retrofitting Protection of Virtual Machines in Multi-tenant Cloud with Nested Virtualization

被引:0
|
作者
Zhang, Fengzhe [1 ]
Chen, Jin [1 ]
Chen, Haibo [1 ]
Zang, Binyu [1 ]
机构
[1] Fudan Univ, Parallel Proc Inst, Shanghai, Peoples R China
来源
SOSP 11: PROCEEDINGS OF THE TWENTY-THIRD ACM SYMPOSIUM ON OPERATING SYSTEMS PRINCIPLES | 2011年
关键词
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Multi-tenant cloud, which usually leases resources in the form of virtual machines, has been commercially available for years. Unfortunately, with the adoption of commodity virtualized infrastructures, software stacks in typical multi-tenant clouds are non-trivially large and complex, and thus are prone to compromise or abuse from adversaries including the cloud operators, which may lead to leakage of security-sensitive data. In this paper, we propose a transparent, backward-compatible approach that protects the privacy and integrity of customers' virtual machines on commodity virtualized infrastructures, even facing a total compromise of the virtual machine monitor (VMM) and the management VM. The key of our approach is the separation of the resource management from security protection in the virtualization layer. A tiny security monitor is introduced underneath the commodity VMM using nested virtualization and provides protection to the hosted VMs. As a result, our approach allows virtualization software (e.g., VMM, management VM and tools) to handle complex tasks of managing leased VMs for the cloud, without breaking security of users' data inside the VMs. We have implemented a prototype by leveraging commercially-available hardware support for virtualization. The prototype system, called Cloud Visor, comprises only 5.5K LOCs and supports the Xen VMM with multiple Linux and Windows as the guest OSes. Performance evaluation shows that Cloud Visor incurs moderate slow-down for I/O intensive applications and very small slowdown for other applications.
引用
收藏
页码:203 / 216
页数:14
相关论文
共 50 条
  • [41] Personalized Cache Management for Multi-Tenant Cloud Services
    Yuan, Yigui
    Jin, Peiquan
    Wan, Shouhong
    2022 IEEE 42ND INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS 2022), 2022, : 1326 - 1327
  • [42] Predictive elastic replication for multi-tenant databases in the cloud
    Sousa, Flavio R. C.
    Moreira, Leonardo O.
    Costa Filho, Jose S.
    Machado, Javam C.
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2018, 30 (16):
  • [43] A Multi-Tenant RBAC Model for Collaborative Cloud Services
    Tang, Bo
    Li, Qi
    Sandhu, Ravi
    2013 ELEVENTH ANNUAL INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2013, : 229 - 238
  • [44] A Scalable VPN Gateway for Multi-Tenant Cloud Services
    Arashloo, Mina Tahmasbi
    Shirshov, Pavel
    Gandhi, Rohan
    Lu, Guohan
    Yuan, Lihua
    Rexford, Jennifer
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2018, 48 (01) : 49 - 55
  • [45] A multi-tenant usage access model for cloud computing
    Liu Z.
    Yang Y.
    Gu W.
    Xia J.
    Computers, Materials and Continua, 2020, 64 (02): : 1233 - 1245
  • [46] Multi-Tenant Data Center and Cloud Networking Evolution
    Bitar, Nabil
    2013 OPTICAL FIBER COMMUNICATION CONFERENCE AND EXPOSITION AND THE NATIONAL FIBER OPTIC ENGINEERS CONFERENCE (OFC/NFOEC), 2013,
  • [47] A multi-tenant hierarchical modeling for cloud computing workload
    An, Chunyan
    Zhou, Jiantao
    Liu, Shuai
    Geihs, Kurt
    INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2016, 22 (04): : 579 - 586
  • [48] Data Placement for Multi-Tenant Data Federation on the Cloud
    Liu, Ji
    Mo, Lei
    Yang, Sijia
    Zhou, Jingbo
    Ji, Shilei
    Xiong, Haoyi
    Dou, Dejing
    IEEE TRANSACTIONS ON CLOUD COMPUTING, 2023, 11 (02) : 1414 - 1429
  • [49] Multi-Tenant Architectures in the Cloud: A Systematic Mapping Study
    Karatas, Gozde
    Can, Ferit
    Dogan, Gamze
    Konca, Cemile
    Akbulut, Akhan
    2017 INTERNATIONAL ARTIFICIAL INTELLIGENCE AND DATA PROCESSING SYMPOSIUM (IDAP), 2017,
  • [50] Workflow Scheduling in Multi-Tenant Cloud Computing Environments
    Rimal, Bhaskar Prasad
    Maier, Martin
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2017, 28 (01) : 290 - 304