• DocumentCode
    3145890
  • Title

    BlueShield: A Layer 2 Appliance for Enhanced Isolation and Security Hardening among Multi-tenant Cloud Workloads

  • Author

    Barjatiya, S. ; Saripalli, P.

  • Author_Institution
    IBM Res. & IIIT, Hyderabad, India
  • fYear
    2012
  • fDate
    5-8 Nov. 2012
  • Firstpage
    195
  • Lastpage
    198
  • Abstract
    Enhanced Isolation and Security (EIS) in a cloud are of significant concern. Many organizations are hesitant in migrating to a cloud based infrastructure due to the perceived limitations with EIS. Earlier, we had presented the quantitative risk and impact assessment framework (QUIRC) [1]. QUIRC can be used to assess the security risks associated with the cloud computing platforms. In the present work, design and implementation of Blue Shield is presented. Blue Shield is a Layer2 appliance for an EIS hardening among multi-tenant cloud workloads. Blue Shield architecture provides EIS, significantly reducing the threats faced by the tenants in a cloud environment. EIS provided by Blue Shield is validated using a proof of concept implementation. Then shortcomings of the various present approaches in addressing the identified security threats are explained. It is shown that the present security applications, deployed in a non-cloud environment, do not require modification during migration to Blue Shield based clouds. Furthermore, the proposed design provides high level of protection among the VMs in the same VLAN.
  • Keywords
    cloud computing; security of data; BlueShield architecture; EIS hardening; QUIRC; VLAN; VM; cloud based infrastructure; cloud computing; cloud environment; enhanced isolation and security; layer 2 appliance; multitenant cloud workload; quantitative risk and impact assessment framework; security application; security risk assessment; security threat; Bandwidth; Cloud computing; Computer architecture; Security; Servers; Unicast; Virtual machine monitors; Auditing; BlueShield; Cloud; Echelon; Enhanced isolation; Multitenant isolation; Network; Security; VM agent;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Utility and Cloud Computing (UCC), 2012 IEEE Fifth International Conference on
  • Conference_Location
    Chicago, IL
  • Print_ISBN
    978-1-4673-4432-6
  • Type

    conf

  • DOI
    10.1109/UCC.2012.21
  • Filename
    6424946