DocumentCode
1709526
Title
Microarchitecture-Aware Virtual Machine Placement under Information Leakage Constraints
Author
Lefray, Arnaud ; Caron, Eddy ; Rouzaud-Cornabas, Jonathan ; Toinard, Christian
Author_Institution
LIP, Univ. of Lyon, Lyon, France
fYear
2015
Firstpage
588
Lastpage
595
Abstract
One of the major concerns when moving to Clouds is data confidentiality. Nevertheless, more and more applications are outsourced to a public or private Cloud. In general, the usage of virtualization is acknowledged as an isolation mechanism between applications running on shared resources. But, as previously shown, virtualization does not ensure data security. Indeed, the isolation can be broken due to covert channels existing in both the software and the hardware (e.g., Improperly virtualized caches). Furthermore, even if a perfect control mechanism could be design, it would not protect against covert channels as they bypass control mechanism using legal means. In this paper, we first describe how these attacks are working. Next, after presenting the existing mitigation mechanisms, we show that a good solution is to take into account security while allocating resources (i.e., When placing the VMs). Furthermore, depending on which resources are shared, we demonstrate that the achievable bit rate of these attacks can change dramatically. We propose a new metric to quantify them and use it as an acceptable risk for isolation properties. Then, we show how to use them when allocating resources and the importance of a fine-grained resource allocation mechanism. Finally, we demonstrate that a security-oblivious placement algorithm breaks a fair amount of properties but taking into account the isolation impacts the acceptance rate (i.e., The percentage of successfully placed VMs).
Keywords
cloud computing; security of data; virtual machines; control mechanism; data conlidentiality; data security; fine-grained resource allocation mechanism; information leakage constraints; isolation properties; microarchitecture-aware virtual machine placement; mitigation mechanisms; private cloud; public cloud; resource allocation; security-oblivious placement algorithm; virtualization; Bit rate; Hardware; Microarchitecture; Resource management; Security; Cloud; Covert channels; Isolation; Microarchitecture; Security; Virtual Machine Placement;
fLanguage
English
Publisher
ieee
Conference_Titel
Cloud Computing (CLOUD), 2015 IEEE 8th International Conference on
Conference_Location
New York City, NY
Print_ISBN
978-1-4673-7286-2
Type
conf
DOI
10.1109/CLOUD.2015.84
Filename
7214094
Link To Document