DocumentCode
3140441
Title
Identification and Evaluation of Sharing Memory Covert Timing Channel in Xen Virtual Machines
Author
Wu, Jingzheng ; Ding, Liping ; Wang, Yongji ; Han, Wei
Author_Institution
Nat. Eng. Res. Center for Fundamental Software, Inst. of Software, China
fYear
2011
fDate
4-9 July 2011
Firstpage
283
Lastpage
291
Abstract
Virtualization technology is the basis of cloud computing, and the most important property of virtualization is isolation. Isolation guarantees security between virtual machines. However, covert channel breaks the isolation and leaks sensitive message covertly. In this paper, we formally model the isolation into noninterference, and define that all the transmission channels violating noninterference are covert channels. With this definition, we present an identification method based on information flow. This method first compiles the source code into a more structured equivalent code with LLVM. And then a search algorithm is proposed to obtain the shared resources and the operational processes in the equivalent code. A new covert channel termed sharing memory covert timing channel (SMCTC) is identified from Xen source code. We construct channel scenario for SMCTC, and evaluate its threat with the metrics of channel capacity and transmission accuracy. The results show that SMCTC is much more threatened than CPU load based and cache based covert channels etc.
Keywords
channel capacity; cloud computing; virtual machines; virtualisation; LLVM; SMCTC; Xen virtual machines; channel capacity; cloud computing; search algorithm; sharing memory covert timing channel; transmission channels; virtualization technology; Cloud computing; Receivers; Security; Software; Timing; Virtual machine monitors; Virtual machining; Channel Identification; Channel Performance Evaluation; Channel Scenario Construction; Cloud Computing; Covert Timing Channel; Xen;
fLanguage
English
Publisher
ieee
Conference_Titel
Cloud Computing (CLOUD), 2011 IEEE International Conference on
Conference_Location
Washington, DC
ISSN
2159-6182
Print_ISBN
978-1-4577-0836-7
Electronic_ISBN
2159-6182
Type
conf
DOI
10.1109/CLOUD.2011.10
Filename
6008721
Link To Document