DocumentCode :
173035
Title :
CryptVMI: Encrypted Virtual Machine Introspection in the Cloud
Author :
Fangzhou Yao ; Campbell, Roy H.
Author_Institution :
Dept. of Comput. Sci., Univ. of Illinois at Urbana-Champaign, Urbana, IL, USA
fYear :
2014
fDate :
June 27 2014-July 2 2014
Firstpage :
977
Lastpage :
978
Abstract :
Virtualization techniques are the key in both public and private cloud computing environments. In such environments, multiple virtual instances are running on the same physical machine. The logical isolation between systems makes security assurance weaker than physically isolated systems. Thus, Virtual Machine Introspection techniques become essential to prevent the virtual system from being vulnerable to attacks. However, this technique breaks down the borders of the segregation between multiple tenants, which should be avoided in a public cloud computing environment. In this paper, we focus on building an encrypted Virtual Machine Introspection system, CryptVMI, to address the above concern, especially in a public cloud system. Our approach maintains a query handler on the management node to handle encrypted queries from user clients. We pass the query to the corresponding compute node that holds the virtual instance queried. The introspection application deployed on the compute node processes the query and acquires the encrypted results from the virtual instance for the user. This work shows our design and preliminary implementation of this system.
Keywords :
cloud computing; cryptography; virtual machines; virtualisation; CryptVMI; encrypted virtual machine introspection system; introspection application; logical isolation; private cloud computing environments; public cloud computing environment; public cloud system; query handler; security assurance; virtual instances; virtualization techniques; Cloud computing; Conferences; Cryptography; Libraries; Virtual machining; Virtualization;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Cloud Computing (CLOUD), 2014 IEEE 7th International Conference on
Conference_Location :
Anchorage, AK
Print_ISBN :
978-1-4799-5062-1
Type :
conf
DOI :
10.1109/CLOUD.2014.149
Filename :
6973855
Link To Document :
بازگشت