A Secure Virtual Machine Deployment Strategy to Reduce Co-residency in Cloud

Yuqin Qiu,Qingni Shen,Yang Luo,Cong Li,Zhonghai Wu
DOI: https://doi.org/10.1109/Trustcom/BigDataSE/ICESS.2017.257
2017-01-01
Abstract:Due to sharing physical resource, the co-residency of virtual machine (VM) in cloud is inevitable, which brings many security threats, such as side channel attacks and covert channel threats. Most of previous work focused on detecting and resisting a bewildering variety of co-resident attacks. Generally, improving the VM deployment strategy can also mitigate the security threats of co-resident attacks effectively by reducing the probability of VM co-residency. In this paper, we propose a co-residency-resistant VM deployment strategy and define four thresholds to adjust the strategy for security and load balancing. Moreover, two metrics(VM co-residency probability and user co-residency coverage probability) are introduced to evaluate the deployment strategy. Finally, we implement the strategy and run experiments on both OpenStack and CloudSim. The results show that our strategy can reduce VM co-residency by 50% to 66.7% and user co-residency by 50% to 66% compared with the existing strategies.
What problem does this paper attempt to address?