Multi-Layered Virtual Machines for Security Updates in Grid Environments

被引:6
作者
Schwarzkopf, Roland [1 ]
Schmidt, Matthias [1 ]
Fallenbeck, Niels [1 ]
Freisleben, Bernd [1 ]
机构
[1] Univ Marburg, Dept Math & Comp Sci, D-35032 Marburg, Germany
来源
2009 35TH EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS, PROCEEDINGS | 2009年
关键词
D O I
10.1109/SEAA.2009.74
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The use of user specific virtual machines (VMs) in Grid and Cloud computing reduces the administration overhead associated with manually installing required software for every user on every computational resource. However, a large number of user specific VMs increases the risk of security attacks. In particular, Cloud computing providers like Amazon suffer from these problems, since they offer different operating systems within VMs and delegate the security update problem for VMs to the users. In this paper, a solution that solves the problem by separating a VM into several layers is presented. The approach creates the possibility of installing security updates into a base layer centrally, affecting all VMs without affecting the users' own installed software stack by merging package databases. The proposal permits resource providers to keep a large number of VMs patched with the latest security fixes without bothering the users. Furthermore, the proposal avoids the overhead for transferring possible large VM images over the network between the nodes of a Grid or Cloud by allowing to hold locally cached VM images with a basic operating system installation while only the user-specific software stack stored in a separate layer needs to be transferred.
引用
收藏
页码:563 / 570
页数:8
相关论文
共 16 条
[1]   The VirtuaLinux storage abstraction layer for efficient virtual clustering [J].
Aldinucci, Marco ;
Torquati, Massimo ;
Vanneschi, Marco ;
Zuccato, Pierfrancesco .
PROCEEDINGS OF THE 16TH EUROMICRO CONFERENCE ON PARALLEL, DISTRIBUTED AND NETWORK-BASED PROCESSING, 2008, :619-+
[2]  
[Anonymous], 2006, VIRTUALIZATION TECHN
[3]  
[Anonymous], BONNIE
[4]  
[Anonymous], gridengine - Project home
[5]  
[Anonymous], Amazon Elastic Compute Cloud
[6]  
KOTSOVINOS E, 2004, 1 WORKS REAL LARG DI
[7]  
Meyer DT, 2008, EUROSYS'08: PROCEEDINGS OF THE EUROSYS 2008 CONFERENCE, P41, DOI 10.1145/1357010.1352598
[8]  
PFAFF B., 2006, NSDI
[9]  
Quigley David., 2006, Proceedings of the 2006 Linux Symposium, P349
[10]   Optimizing the migration of virtual computers [J].
Sapuntzakis, CP ;
Chandra, R ;
Pfaff, B ;
Chow, J ;
Lam, MS ;
Rosenblum, M .
USENIX ASSOCIATION PROCEEDINGS OF THE FIFTH SYMPOSIUM ON OPERATING SYSTEMS DESIGN AND IMPLEMENTATION, 2002, :377-390