DocumentCode :
113407
Title :
C3-Sched — A cache covert channel robust cloud computing scheduler
Author :
Betz, Johann ; Westhoff, Dirk
Author_Institution :
Hochschule Furtwangen Univ., Furtwangen, Germany
fYear :
2014
fDate :
8-10 Dec. 2014
Firstpage :
54
Lastpage :
60
Abstract :
Several cloud schedulers have been proposed in the literature with different optimization goals such as reducing power consumption, reducing the overall operational costs or decreasing response times. A less common goal is to enhance the system security by applying specific scheduling decisions. The security risk of covert channels is known for quite some time, but is now back in the focus of research because of the multitenant nature of cloud computing and the co-residency of several per-tenant virtual machines on the same physical machine. Especially several cache covert channels have been identified that aim to bypass a cloud infrastructure´s sandboxing mechanism. For instance, cache covert channels like the one proposed by Xu et. al. use the idealistic scenario with two alternately running colluding processes in different VMs accessing the cache to transfer bits by measuring cache access time. Therefore, in this paper we present a cascaded cloud scheduler coined C3-Sched aiming at mitigating the threat of a leakage of customers data via cache covert channels by preventing processes to access cache lines alternately. At the same time we aim at maintaining the cloud performance and minimizing the global scheduling overhead.
Keywords :
cache storage; cloud computing; security of data; virtual machines; C3-Sched; cache access time measurement; cache covert channel; cloud infrastructure sandboxing mechanism; operational cost reducing; pertenant virtual machine; power consumption; response time; robust cloud computing scheduler; security risk; system security; Cloud computing; Noise; Pollution; Processor scheduling; Receivers; Security; Virtual machining; Cloud; Covert Channel; Scheduler; Virtual Machine;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Internet Technology and Secured Transactions (ICITST), 2014 9th International Conference for
Conference_Location :
London
Type :
conf
DOI :
10.1109/ICITST.2014.7038775
Filename :
7038775
Link To Document :
بازگشت