CyberGuarder: A virtualization security assurance architecture for green cloud computing
نویسندگان
چکیده
With energy and power costs increasing as the size of IT infrastructures grows, virtualization technologies enable scalable management for large scale of virtual machines running on physical systems, and virtualizationbased green cloud computing paradigm is springing up to provide a scalable and energy-efficient network software application (NetApp in short) supplement, consumption, delivery mode. However, the security problems will become more serious because data and infrastructures are fully shared among multi-tenant in a green cloud computing environment. Moreover security services generally affect the system's energy consumption and computing power. The success or failure of a practical application of a green cloud computing infrastructure strongly relies on its security solution. In this paper, we analyze the key security challenges faced by existing green cloud computing environments, and design a virtualization security assurance architecture named CyberGuarder to address the security problems with consideration of energy efficiency. In CyberGuarder, we provide three kinds of services from different security aspects. First, we propose a novel virtual machine security service incorporating a number of new techniques including 1) a VMM-based integrity measurement approach for a NetApp trusted loading, 2) a multi-granularity NetApps isolation mechanism for OS user isolation, 3) VM (Virtual Machine) isolation and virtual network isolation of multiple NetApps according to dynamic energyefficiency and security needs. Second, we successfully developed a virtual network security service which provides an adaptive virtual security appliance deployment in the NetApp execution environment, and traditional security systems such as IDS, firewall etc. can be encapsulated into VM images and deployed into a virtual network in accordance with the utilization of virtualization infrastructure. Last, a security policy based trust management mechanism is proposed for access control to a resource pool and a trust federation mechanism across multiple resource pools to optimize the tradeoff between task privacy and computing cost requirements. We have studied these approaches in our iVIC platform, and some preliminary implementation experiments show that our approaches are effective and useful. Currently, we are building a virtual lab for our campus courses experiment based on our green cloud computing infrastructure iVIC, and CyberGuarder is an important virtualization security assurance system for the practical operation of iVIC platform. Index Terms — Cloud Computing, Green Computing, Virtualization, Virtual Security Appliance, Security Isolation.
منابع مشابه
A Survey on Security Assurance Architecture in Virtualization implementation on Cloud
Cloud computing is a natural extension of virtualisation technologies that enable scalable management of virtual machines over a massive physically connected systems. The virtualisation-based cloud computing paradigm offers a practical approach to green IT/clouds, which emphasise the construction and deployment of scalable, energy-efficient network software applications (NetApp) by virtue of im...
متن کاملEnergy Aware Resource Management of Cloud Data Centers
Cloud Computing, the long-held dream of computing as a utility, has the potential to transform a large part of the IT industry, making software even more attractive as a service and shaping the way IT hardware is designed and purchased. Virtualization technology forms a key concept for new cloud computing architectures. The data centers are used to provide cloud services burdening a significant...
متن کاملAssessment Methodology for Anomaly-Based Intrusion Detection in Cloud Computing
Cloud computing has become an attractive target for attackers as the mainstream technologies in the cloud, such as the virtualization and multitenancy, permit multiple users to utilize the same physical resource, thereby posing the so-called problem of internal facing security. Moreover, the traditional network-based intrusion detection systems (IDSs) are ineffective to be deployed in the cloud...
متن کاملGreen Cloud Computing: A Virtualized Security Framework for Green Cloud Computing
In the IT industry’s there is forcefully demand of the technology known as Cloud computing. It is an emerging trend in computing. There are huge data centres are used in big industries. Environmentally, these systems can produce e-wastes, harmful gases with heat. This paper focuses on security in such a power saving data centres in the enterprises we called them as Green Cloud Computers. We hav...
متن کاملA review of methods for resource allocation and operational framework in cloud computing
The issue of management and allocation of resources in cloud computing environments, according to the breadth of scale and modern technology implementation, is a complicated issue. Issues such as: the heterogeneity of resources, resource dependencies to each other, the dynamics of the environment, virtualization, workload diversity as well as a wide range of management objectives of cloud servi...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- Future Generation Comp. Syst.
دوره 28 شماره
صفحات -
تاریخ انتشار 2012