• DocumentCode
    2868548
  • Title

    Energy Consumption Side-Channel Attack at Virtual Machines in a Cloud

  • Author

    Hlavacs, Helmut ; Treutner, Thomas ; Gelas, Jean-Patrick ; Lefèvre, Laurent ; Orgerie, Anne-Cécile

  • Author_Institution
    Res. Group Entertainment Comput., Univ. of Vienna, Vienna, Austria
  • fYear
    2011
  • fDate
    12-14 Dec. 2011
  • Firstpage
    605
  • Lastpage
    612
  • Abstract
    Virtualized data centers where several virtual machines (VMs) are hosted per server are becoming more popular due to Cloud Computing. As a consequence of energy efficiency concerns, the exact combination of VMs running on a specific server will most likely change over time. We present experimental results how to use the energy/power consumption logs of a power monitored server as a side-channel that allows us to recognize the exact combination of VMs it currently hosts to a high degree. For classification, we use a maximum log-likelihood approach, which works well for comparably small training and test set sizes. We also show to which degree a specific VM can be recognized, regardless of other VMs currently running on the same server, and show false negative/positive rates. To cross-validate our results, we have used a Kolmogorov-Smirnov test, resulting in comparable quality of recognition within shorter time. In order to clarify whether our approach is generalizable and yields reproducible results, we have set up a second experimental infrastructure in Lyon, using a different hardware platform and power measurement device. We have obtained similar results and have experimented with different CPU frequency scaling governors, yielding comparable quality of recognition. As a result, energy consumption data of servers must be protected carefully, as it is potentially valuable information for an attacker trying to track down a VM to mount further attack steps.
  • Keywords
    cloud computing; power aware computing; virtual machines; Kolmogorov-Smirnov test; VM; cloud computing; data centers; energy consumption side channel attack; energy efficiency; energy/power consumption; hardware platform; power measurement device; power monitored server; virtual machines; Cloud computing; Energy consumption; Energy measurement; Power demand; Power measurement; Servers; Virtual machine monitors;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable, Autonomic and Secure Computing (DASC), 2011 IEEE Ninth International Conference on
  • Conference_Location
    Sydney, NSW
  • Print_ISBN
    978-1-4673-0006-3
  • Type

    conf

  • DOI
    10.1109/DASC.2011.110
  • Filename
    6119058