DocumentCode :
2350994
Title :
HomeAlone: Co-residency Detection in the Cloud via Side-Channel Analysis
Author :
Zhang, Yinqian ; Juels, Ari ; Oprea, Alina ; Reiter, Michael K.
Author_Institution :
Univ. of North Carolina, Chapel Hill, NC, USA
fYear :
2011
fDate :
22-25 May 2011
Firstpage :
313
Lastpage :
328
Abstract :
Security is a major barrier to enterprise adoption of cloud computing. Physical co-residency with other tenants poses a particular risk, due to pervasive virtualization in the cloud. Recent research has shown how side channels in shared hardware may enable attackers to exfiltrate sensitive data across virtual machines (VMs). In view of such risks, cloud providers may promise physically isolated resources to select tenants, but a challenge remains: Tenants still need to be able to verify physical isolation of their VMs. We introduce Home Alone, a system that lets a tenant verify its VMs\´ exclusive use of a physical machine. The key idea in Home Alone is to invert the usual application of side channels. Rather than exploiting a side channel as a vector of attack, Home Alone uses a side-channel (in the L2 memory cache) as a novel, defensive detection tool. By analyzing cache usage during periods in which "friendly" VMs coordinate to avoid portions of the cache, a tenant using Home Alone can detect the activity of a co-resident "foe" VM. Key technical contributions of Home Alone include classification techniques to analyze cache usage and guest operating system kernel modifications that minimize the performance impact of friendly VMs sidestepping monitored cache portions. Home Alone requires no modification of existing hyper visors and no special action or cooperation by the cloud provider.
Keywords :
cache storage; cloud computing; formal verification; operating system kernels; security of data; ubiquitous computing; virtual machines; virtualisation; HomeAlone; L2 memory cache; cache usage; cloud computing; co-residency detection; co-resident foe VM activity detection; defensive detection tool; guest operating system kernel modifications; pervasive virtualization; physical co-residency; side-channel analysis; virtual machines; Cloud computing; Hardware; Monitoring; Probes; Timing; Virtual machine monitors; Virtual machining; Cloud computing; Infrastructure-as-a-Service (IaaS); co-residency detection; side-channel analysis;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Security and Privacy (SP), 2011 IEEE Symposium on
Conference_Location :
Berkeley, CA
ISSN :
1081-6011
Print_ISBN :
978-1-4577-0147-4
Electronic_ISBN :
1081-6011
Type :
conf
DOI :
10.1109/SP.2011.31
Filename :
5958037
Link To Document :
بازگشت