Hey, you, get off of my cloud: exploring information leakage in third-party compute clouds

Hey, you, get off of my cloud: exploring information leakage in third-party compute clouds
复制标题

DOI:
10.1145/1653662.1653687
复制
发表时间:
2009-11
期刊:
--
影响因子:
--
通讯作者:
Thomas Ristenpart;Eran Tromer;H. Shacham;S. Savage
Thomas Ristenpart;Eran Tromer;H. Shacham;S. Savage
中科院分区:
其他
文献类型:
--
作者:
Thomas Ristenpart;Eran Tromer;H. Shacham;S. Savage

文献摘要

被引文献

相似文献

第三方云计算代表了外包应用于计算的承诺。服务,如微软的Azure和亚马逊的EC2,允许用户按需实例化虚拟机(vm),从而在需要时精确地购买所需的容量。反过来,虚拟化的使用允许第三方云提供商通过在共享的物理基础设施上复用许多客户vm来最大限度地利用他们的沉没资本成本。然而,在本文中,我们表明这种方法也可能引入新的漏洞。使用Amazon EC2服务作为案例研究,我们展示了可以映射内部云基础设施,确定特定目标VM可能驻留的位置,然后实例化新的VM,直到一个VM与目标共同驻留。我们将探讨如何使用这种放置来安装跨VM侧通道攻击,以从同一台机器上的目标VM提取信息。
Third-party cloud computing represents the promise of outsourcing as applied to computation. Services, such as Microsoft's Azure and Amazon's EC2, allow users to instantiate virtual machines (VMs) on demand and thus purchase precisely the capacity they require when they require it. In turn, the use of virtualization allows third-party cloud providers to maximize the utilization of their sunk capital costs by multiplexing many customer VMs across a shared physical infrastructure. However, in this paper, we show that this approach can also introduce new vulnerabilities. Using the Amazon EC2 service as a case study, we show that it is possible to map the internal cloud infrastructure, identify where a particular target VM is likely to reside, and then instantiate new VMs until one is placed co-resident with the target. We explore how such placement can then be used to mount cross-VM side-channel attacks to extract information from a target VM on the same machine.