• DocumentCode
    688261
  • Title

    A Security-Awareness Virtual Machine Placement Scheme in the Cloud

  • Author

    Si Yu ; Xiaolin Gui ; Feng Tian ; Pan Yang ; Jianqiang Zhao

  • Author_Institution
    Sch. of Electron. & Inf. Eng., Xi´an Jiaotong Univ., Xi´an, China
  • fYear
    2013
  • fDate
    13-15 Nov. 2013
  • Firstpage
    1078
  • Lastpage
    1083
  • Abstract
    Recent work reveals that side channel attacks (SCA) can lead to leakage of user privacy in the cloud. Enhancing the isolation between users is an effective solution to eliminate the attacks. However, to achieve the stronger isolation, the existing schemes require the sophisticated decision making systems and specific monitoring systems, which may degrade the efficiency of the system. In this paper, to eliminate the SCA, we investigate the isolation enhancement from a novel perspective - VM placement. And the security-awareness VMs placement scheme (SVMPS) is proposed. In this scheme, we use the aggressive conflict of interest relation (ACIR) to describe the constraint relations for users, based on the Chinese wall policy, we put forward the isolation rules to formulate the VMs placement behavior, according to the isolation rules, we design the VMs placement solution calculated algorithm to enforce the VMs placement. The experimental results demonstrate that SVMPS is efficient in guaranteeing the isolation between conflict users, while the resource utilization rate decreases not too much.
  • Keywords
    cloud computing; data privacy; decision making; security of data; virtual machines; virtualisation; ACIR; Chinese wall policy; SCA; SVMPS; aggressive conflict of interest relation; cloud computing; constraint relations; decision making system; isolation enhancement; isolation rules; monitoring systems; security awareness virtual machine placement scheme; side channel attack; user privacy leakage; Access control; Algorithm design and analysis; Resource management; Time-domain analysis; Virtual machining; Virtualization; VM placement; cloud computing; isolation; side channel attacks; virtualization security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    High Performance Computing and Communications & 2013 IEEE International Conference on Embedded and Ubiquitous Computing (HPCC_EUC), 2013 IEEE 10th International Conference on
  • Conference_Location
    Zhangjiajie
  • Type

    conf

  • DOI
    10.1109/HPCC.and.EUC.2013.152
  • Filename
    6832034