Skip to main content
QUICK REVIEW

[论文解读] an intelligent security centered resource-efficient resource management model for cloud computing environments

Deepika Saxena, Ashutosh Kumar Singh|arXiv (Cornell University)|Oct 29, 2022
Cloud Computing and Resource Management被引用 5
一句话总结

本文提出了一种面向云计算的智能、以安全为中心的资源管理模型,通过实时检测未经授权的虚拟机访问和通信,优化虚拟机分配以实现性能与能效的平衡,同时防止数据泄露。该模型整合了安全的虚拟机管理单元、工作负载分析器以及动态虚拟机迁移机制,以减少攻击面和系统开销,在安全性和效率方面优于传统的加密和隧道技术。

ABSTRACT

This paper proposes a conceptual model for a secure and performance-efficient workload management model in cloud environments. In this model, a resource management unit is employed for energy and performance proficient allocation of virtual machines while ensuring the secure processing of users' applications by defending against data breaches due to unauthorized access to virtual machines in real-time. The resource management unit is guided by a secure virtual machine management unit which is designed to generate information regarding unauthorized access or inter-communication links among active virtual machines. Also, a workload analyzer unit operates concurrently to estimate resource utilization information to assist the resource management unit in the performance-efficient allocation of virtual machines. Contrary to prior works which engage access control mechanisms, encryption, and decryption of data before the transfer and the use of tunneling for prevention of unauthorized access to virtual machines which raises excess computational cost overhead, the proposed model operates diversely for efficiently serving the same purpose.

研究动机与目标

  • 解决多租户云环境因虚拟机未经授权访问和同驻攻击导致的数据泄露这一关键挑战。
  • 通过在虚拟化层集成主动威胁检测,降低传统安全机制(如加密、隧道和访问控制)的计算开销。
  • 通过工作负载预测和动态整合,实现性能高效且节能的虚拟机分配。
  • 在确保强数据机密性和完整性的同时,维持云数据中心的高可扩展性和可靠性。
  • 降低因虚拟机监控程序漏洞和共享物理基础设施配置错误导致的敏感数据泄露风险。

提出的方法

  • 基于工作负载预测和安全约束,资源管理单元动态分配虚拟机。
  • 安全虚拟机管理单元实时监控并记录未经授权的访问尝试以及虚拟机间的通信链路。
  • 工作负载分析单元估算资源利用率,以指导性能高效的虚拟机部署和迁移决策。
  • 该模型使用集中式的可信虚拟机访问数据库(AVAD)来维护和验证虚拟机之间的可信通信路径。
  • 基于安全风险评分和资源利用率趋势触发虚拟机迁移,以防止同驻攻击。
  • 通过聚焦于虚拟机监控程序层面的访问控制和异常检测,避免传统加密和隧道技术带来的开销。

实验结果

研究问题

  • RQ1如何使云资源管理在实现节能的同时,有效防范未经授权的虚拟机访问和数据泄露?
  • RQ2哪些机制可在不产生高计算开销的前提下检测并防止基于同驻的攻击?
  • RQ3如何将工作负载预测与虚拟机整合机制同实时安全监控相结合,以提升整体系统效率?
  • RQ4安全感知的虚拟机部署策略是否可减少云环境中对加密和隧道技术的依赖?
  • RQ5实时访问监控对虚拟机迁移决策和资源利用率有何影响?

主要发现

  • 所提出的模型降低了对计算开销较大的加密和隧道机制的依赖,显著减少了运营开销。
  • 对虚拟机访问和通信链路的实时监控可实现对潜在数据外泄或横向移动攻击的早期检测。
  • 基于安全风险和利用率指标的动态虚拟机迁移,同时提升了安全性和资源效率。
  • 将工作负载预测与安全监控相结合,可实现更稳定、可扩展的虚拟机分配决策。
  • 该模型在不损害性能或能效的前提下,有效缓解了共驻虚拟机间的数据泄露风险。
  • 通过在AVAD中集中管理访问控制,系统在保持强访问策略的同时,最大限度减少了配置错误。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。