...
首页> 外文期刊>Parallel and Distributed Systems, IEEE Transactions on >Swiper: Exploiting Virtual Machine Vulnerability in Third-Party Clouds with Competition for I/O Resources
【24h】

Swiper: Exploiting Virtual Machine Vulnerability in Third-Party Clouds with Competition for I/O Resources

机译:Swiper:通过争夺I / O资源来利用第三方云中的虚拟机漏洞

获取原文
获取原文并翻译 | 示例
           

摘要

The emerging paradigm of cloud computing, e.g., Amazon Elastic Compute Cloud (EC2), promises a highly flexible yet robust environment for large-scale applications. Ideally, while multiple virtual machines (VM) share the same physical resources (e.g., CPUs, caches, DRAM, and I/O devices), each application should be allocated to an independently managed VM and isolated from one another. Unfortunately, the absence of physical isolation inevitably opens doors to a number of security threats. In this paper, we demonstrate in EC2 a new type of security vulnerability caused by competition between virtual I/O workloads—i.e., by leveraging the competition for shared resources, an adversary could intentionally slow down the execution of a targeted application in a VM that shares the same hardware. In particular, we focus on I/O resources such as hard-drive throughput and/or network bandwidth—which are critical for data-intensive applications. We design and implement , a framework which uses a carefully designed workload to incur significant delays on the targeted application and VM with minimum cost (i.e., resource consumption). We conduct a comprehensive set of experiments in EC2, which clearly demonstrates that Swiper is capable of significantly slowing down various server applications while consuming a small amount of resources.
机译:云计算的新兴范例,例如Amazon Elastic Compute Cloud(EC2),为大型应用程序提供了高度灵活而健壮的环境。理想情况下,尽管多个虚拟机(VM)共享相同的物理资源(例如CPU,缓存,DRAM和I / O设备),但每个应用程序应分配给独立管理的VM,并且彼此隔离。不幸的是,缺乏物理隔离不可避免地为许多安全威胁打开了大门。在本文中,我们在EC2中演示了一种由虚拟I / O工作负载之间的竞争引起的新型安全漏洞,即,通过利用对共享资源的竞争,对手可能有意减慢VM中目标应用程序的执行速度,共享相同的硬件。特别是,我们专注于I / O资源,例如硬盘驱动器吞吐量和/或网络带宽,这对于数据密集型应用程序至关重要。我们设计并实现了一个框架,该框架使用经过精心设计的工作负载以最小的成本(即资源消耗)在目标应用程序和VM上造成重大延迟。我们在EC2中进行了一套全面的实验,清楚地表明Swiper能够显着减慢各种服务器应用程序的速度,同时消耗少量资源。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号