CyberGuarder: A virtualization security assurance architecture for green cloud computing

被引:92
作者
Li, Jianxin [1 ]
Li, Bo [1 ,4 ]
Wo, Tianyu [1 ]
Hu, Chunming [1 ]
Huai, Jinpeng [1 ]
Liu, Lu [2 ]
Lam, K. P. [3 ]
机构
[1] Beihang Univ, Sch Comp Sci & Eng, Beijing, Peoples R China
[2] Univ Derby, Sch Comp & Math, Derby DE22 1GB, England
[3] Univ Keele, Sch Comp & Math, Keele ST5 5BG, Staffs, England
[4] Beihang Univ, Dept Comp Sci, Beijing, Peoples R China
来源
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE | 2012年 / 28卷 / 02期
关键词
Cloud computing; Green computing; Virtualization; Virtual security appliance; Security isolation;
D O I
10.1016/j.future.2011.04.012
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
As the sizes of IT infrastructure continue to grow, cloud computing is a natural extension of virtualisation technologies that enable scalable management of virtual machines over a plethora of physically connected systems. The so-called virtualisation-based cloud computing paradigm offers a practical approach to green IT/clouds, which emphasise the construction and deployment of scalable, energy-efficient network software applications (NetApp) by virtue of improved utilisation of the underlying resources. The latter is typically achieved through increased sharing of hardware and data in a multi-tenant cloud architecture/environment and, as such, accentuates the critical requirement for enhanced security services as an integrated component of the virtual infrastructure management strategy. This paper analyses the key security challenges faced by contemporary green cloud computing environments, and proposes a virtualisation security assurance architecture, CyberGuarder, which is designed to address several key security problems within the 'green' cloud computing context. In particular, CyberGuarder provides three different kinds of services: namely, a virtual machine security service, a virtual network security service and a policy based trust management service. Specifically, the proposed virtual machine security service incorporates a number of new techniques which include (1) a VMM-based integrity measurement approach for NetApp trusted loading, (2) a multi-granularity NetApp isolation mechanism to enable OS user isolation, and (3) a dynamic approach to virtual machine and network isolation for multiple NetApp's based on energy-efficiency and security requirements. Secondly, a virtual network security service has been developed successfully to provide an adaptive virtual security appliance deployment in a NetApp execution environment, whereby traditional security services such as IDS and firewalls can be encapsulated as VM images and deployed over a virtual security network in accordance with the practical configuration of the virtualised infrastructure. Thirdly, a security service providing policy based trust management is proposed to facilitate access control to the resources pool and a trust federation mechanism to support/optimise task privacy and cost requirements across multiple resource pools. Preliminary studies of these services have been carried out on our iVIC platform, with promising results. As part of our ongoing research in large-scale, energy-efficient/green cloud computing, we are currently developing a virtual laboratory for our campus courses using the virtualisation infrastructure of iVIC, which incorporates the important results and experience of CyberGuarder in a practical context. (C) 2011 Elsevier B.V. All rights reserved.
引用
收藏
页码:379 / 390
页数:12
相关论文
共 26 条
[1]  
[Anonymous], 2009, P 2009 C USENIX ANN
[2]  
[Anonymous], 2005, P HOTOS2005 10 WORKS
[3]  
[Anonymous], 2009, DEP ELECT ENG COMPUT
[4]  
Ashlesha Joshi, 2005, P 20 ACM S OP SYST P
[5]  
Azab A.M., 2009, P 25 ANN COMP SEC AP
[6]   Cloud computing and emerging IT platforms: Vision, hype, and reality for delivering computing as the 5th utility [J].
Buyya, Rajkumar ;
Yeo, Chee Shin ;
Venugopal, Srikumar ;
Broberg, James ;
Brandic, Ivona .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2009, 25 (06) :599-616
[7]  
Chu CL, 2009, INT C POWER ELECT DR, P172
[8]   Analyzing security and energy tradeoffs in autonomic capacity management [J].
Cunha, Italo ;
Viana, Itamar ;
Palotti, Jaao ;
Almeida, Jussara ;
Almeida, Virgilio .
2008 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, VOLS 1 AND 2, 2008, :302-309
[9]  
Flavio L., 2009, P 2009 ACM S APPL CO
[10]  
FRANCIS K, GREEN MATURITY MODEL