Title :
Trust-based grouping for cloud datacenters: Improving security in shared infrastructures
Author :
Stefani Marcon, Daniel ; Ruas Oliveira, Rodrigo ; Cardoso Neves, Miguel ; Salete Buriol, Luciana ; Gaspary, Luciano Paschoal ; Pilla Barcellos, Marinho
Author_Institution :
Inst. of Inf., Fed. Univ. of Rio Grande do Sul, Porto Alegre, Brazil
Abstract :
Cloud computing can offer virtually unlimited resources without any upfront capital investment through a payper-use pricing model. However, the shared nature of multitenant cloud datacenter networks enables unfair or malicious use of the intra-cloud network by tenants, allowing attacks against the privacy and integrity of data and the availability of resources. In this paper, we introduce a resource allocation strategy that increases the security of network resource sharing among tenant applications. The key idea behind the strategy is to group applications of mutually trusting users into virtual infrastructures (logically isolated domains composed of a set of virtual machines as well as the virtual network interconnecting them). This provides some level of isolation and higher security. However, the use of groups may lead to fragmentation and negatively affect resource utilization. We study the associated trade-off and feasibility of the proposed approach. Evaluation results show the benefits of our strategy, which is able to offer better network resource protection against attacks with low extra cost.
Keywords :
cloud computing; computer centres; computer network security; data integrity; data privacy; pricing; resource allocation; virtual machines; cloud computing; data integrity; data privacy; intracloud network; multitenant cloud datacenter networks; network resource protection; network resource sharing security; pay-per-use pricing model; resource allocation strategy; resource availability; resource utilization; shared infrastructure security; tenant applications; trust-based grouping; user mutual trust; virtual infrastructures; virtual machines; virtually unlimited resources; Bandwidth; Network topology; Resource management; Security; Substrates; Switches; Virtual machining;
Conference_Titel :
IFIP Networking Conference, 2013
Conference_Location :
Brooklyn, NY