DocumentCode :
244091
Title :
CloudFlow: Cloud-wide Policy Enforcement Using Fast VM Introspection
Author :
Baig, Mirza Basim ; Fitzsimons, Connor ; Balasubramanian, S. ; Sion, Radu ; Porter, Donald E.
Author_Institution :
Dept. of Comput. Sci., Stony Brook Univ., Stony Brook, NY, USA
fYear :
2014
fDate :
11-14 March 2014
Firstpage :
159
Lastpage :
164
Abstract :
Government and commercial enterprises are increasingly considering cloud adoption. Clouds improve overall efficiency by consolidating a number of different clients´ software virtual machines onto a smaller set of hardware resources. Unfortunately, this shared hardware also creates inherent side-channel vulnerabilities, which an attacker can use to leak information from a victim VM. Side-channel vulnerabilities are especially concerning when different principals are constrained by regulations. A classic example of these regulations are Chinese Wall policies for financial companies, which aim to protect the financial system from illicit manipulation by separating portions of the business with conflicting interests. Although efficient prevention of side channels is difficult within a single node, there is a unique opportunity within a cloud. This paper proposes a low-overhead approach to cloud wide information flow policy enforcement: identifying side channels which could potentially be used to violate a security policy through run-time introspection, and reactively migrating virtual machines to eliminate node-level side-channels. In this paper we describe CloudFlow-an information flow control extension for OpenStack. CloudFlow includes a novel, virtual machine introspection mechanism that is orders of magnitude faster than previous approaches. CloudFlow efficiently and transparently enforces information flow policies cloud-wide, including information leaks through undesirable side-channels. Additionally, CloudFlow has potential uses for cloud management and resource-efficient virtual machine scheduling.
Keywords :
cloud computing; security of data; virtual machines; Chinese Wall policies; CloudFlow; VM introspection; client software virtual machines; cloud management; cloud-wide information flow policy enforcement; cloud-wide policy enforcement; commercial enterprises; financial companies; financial system; government enterprises; hardware resources; information flow control extension; low-overhead approach; node-level side-channel elimination; resource-efficient virtual machine scheduling; run-time introspection; security policy; side channel prevention; side-channel vulnerabilities; virtual machine introspection mechanism; Cloud computing; Companies; Hardware; Libraries; Runtime; Security; Virtual machining; Cloud computing; Information flow control; Side-Channel Attacks; VM Introspection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Cloud Engineering (IC2E), 2014 IEEE International Conference on
Conference_Location :
Boston, MA
Type :
conf
DOI :
10.1109/IC2E.2014.64
Filename :
6903470
Link To Document :
بازگشت