BMCArmor: A Hardware Protection Scheme for Bare-Metal Clouds

BMCArmor: A Hardware Protection Scheme for Bare-Metal Clouds
复制标题

BMCArmor:裸机云硬件保护方案

DOI:
10.1109/cloudcom.2017.43
复制
发表时间:
2017
期刊:
2017 IEEE International Conference on Cloud Computing Technology and Science (CloudCom)
影响因子:
--
通讯作者:
Kazuhiko Kato
Kazuhiko Kato
中科院分区:
--
文献类型:
--
作者:
Takaaki Fukai;Satoru Takekoshi;Kohei Azuma;Takahiro Shinagawa;Kazuhiko Kato

文献摘要

相似文献

传统的基础设施即服务(IaaS)云提供虚拟机作为服务器。然而,虚拟化会带来性能开销,并阻碍硬件功能的最大化利用,因此一些IaaS供应商已经启动了称为“裸金属云”的新服务,提供物理机而不是虚拟机,允许用户直接访问云中的物理硬件。不幸的是,向用户公开物理硬件会给云供应商带来硬件保护问题。由于物理硬件使用非易失性存储器(NVM)来存储固件代码和配置数据,因此这也暴露给用户。如果NVM被恶意用户修改,硬件可能会被恶意软件永久损坏或感染而不被注意到。这对于云供应商来说是很难预防的,因为裸金属云没有虚拟化层来保护他们的硬件。在本文中,我们描述了可能对裸机云的攻击类型,并提出了BMCArmor,一种针对裸机云的硬件保护方案。BMCArmor使用一个瘦的虚拟机管理程序,它不虚拟化硬件,只是防止访问NVM。实验结果表明,BMCArmor可以成功地保护硬件,同时产生很小的性能开销。
Traditional infrastructure-as-a-service (IaaS) clouds provide virtual machines as servers. However, virtualization incurs a performance overhead and prevents maximum utilization of hardware functions, so several IaaS vendors have started new services called bare-metal clouds that provide physical rather than virtual machines, allowing users to have direct access to physical hardware in the cloud. Unfortunately, exposing physical hardware to users causes a hardware protection issue for cloud vendors. Since physical hardware uses non-volatile memory (NVM) to store firmware code and configuration data, this is also exposed to users. If the NVM is modified by malicious users, the hardware could be permanently corrupted or infected by malware without being noticed. This is difficult for cloud vendors to prevent because bare-metal clouds have no virtualization layer to protect their hardware. In this paper, we describe the types of attacks that are possible for bare-metal clouds and propose BMCArmor, a hardware protection scheme for baremetal clouds. BMCArmor uses a thin hypervisor that does not virtualize the hardware, just preventing access to NVM. Our experiments show that BMCArmor can successfully protect hardware while incurring little performance overhead.