Deakin University
Browse

CloudController: a writable and heterogeneous-adaptive virtual machine introspection for cloud management

Version 2 2024-06-06, 12:07
Version 1 2017-09-07, 00:00
conference contribution
posted on 2024-06-06, 12:07 authored by W Qiang, G Xu, G Sun, T Zhu, H Jin
Virtual machine introspection (VMI) is a critical functionality for cloud management because of the capability of security monitoring. Recently, a concept of writable VMI was proposed to update the state of guest OS from out-of-VM, which is suitable for an automated cloud management due to the feature of high automation. However, current solution of writable VMI lacks practicability because it has high overhead, fails to monitor disk data, and requires the guest OSes between monitoring VM and monitored VM are identical. In this paper, we present CloudController, a writable and heterogeneous-adaptive VMI framework, in which the semantic gap is bridged through redirecting crucial system call issued by introspection processes into the monitored VM. CloudController can be directly applied to automated cloud management due to its writability and heterogeneous-adaptivity (simultaneously monitoring multiple VMs with heterogeneous guest OSes). Besides, CloudController is secure enough to defend against a variety of attacks. To highlight the writability of CloudController, we have developed some applications based on it to automatically secure the guest OSes. We have systematically evaluated CloudController and the experimental results show that it is effective and practical for cloud and its performance overhead is negligible compared to most existing VMI prototypes.

History

Related Materials

Location

Sydney, N.S.W.

Language

eng

Publication classification

E Conference publication, E1 Full written paper - refereed

Copyright notice

2017, IEEE

Editor/Contributor(s)

[Unknown]

Pagination

177-184

Start date

2017-08-01

End date

2017-08-04

ISBN-13

9781509049059

Title of proceedings

Trustcom/BigDataSE/ICESS 2017 : Proceedings 16th IEEE International Conference on Trust, Security and Privacy in Computing and Communications, 11th IEEE International Conference on Big Data Science and Engineering and 14th IEEE International Conference on Embedded Software and Systems

Event

IEEE Computer Society. Conference (2017 : Sydney, N.S.W.)

Publisher

Institute of Electrical and Electronics Engineers

Place of publication

Piscataway, N.J.

Series

IEEE Computer Society Conference