Cloud Armor: Protecting Cloud Commands from Compromised Cloud Services

Cloud Armor: Protecting Cloud Commands from Compromised Cloud Services
复制标题

Cloud Armor:保护云命令免受云服务受损

DOI:
10.1109/cloud.2015.42
复制
发表时间:
2015
期刊:
2015 IEEE 8th International Conference on Cloud Computing
影响因子:
--
通讯作者:
Joshua Schiffman
Joshua Schiffman
中科院分区:
--
文献类型:
--
作者:
Yuqiong Sun;Giuseppe Petracca;T. Jaeger;H. Vijayakumar;Joshua Schiffman

文献摘要

参考文献

被引文献

相似文献

基础设施即服务(IaaS)云可以被视为云服务的分布式系统,该系统被委托执行用户的云命令来配置和管理云计算资源(例如,VM)。然而,最近在云服务中发现的漏洞表明,这种信任常常是错误的。通过利用云服务中的漏洞,攻击者可以劫持或伪造命令来修改用户虚拟机、泄露敏感信息,甚至修改其他服务主机。本文介绍了Cloud Armor,这是一个无需修改云服务即可检测并阻止用户命令篡改的系统。我们的见解是,我们可以构建状态机模型来限制云服务执行的系统调用序列。通过对系统调用参数应用约束,我们可以限制用户命令的执行方式,阻止来自受损云服务的未经授权的操作。我们为 Open Stack(一个广泛采用的开源云平台)实现了原型 Cloud Armor 系统。结果表明,Cloud Armor 可以极大地限制对手可用的攻击选项,同时为用户虚拟机带来不到 1% 的开销。因此,即使云服务受到威胁,云用户也可以利用 Cloud Armor 安全地执行用户命令。
Infrastructure-as-a-Service (IaaS) clouds can be viewed as distributed systems of cloud services that are entrusted to execute users' cloud commands to provision and manage clouds computing resources (e.g., VM). However, recent vulnerabilities found in cloud services show that this trust is often misplaced. By exploiting a vulnerability in a cloud service, an adversary can hijack or forge commands to modify user VMs, exfiltrate sensitive information, and even modify other service hosts. This paper introduces Cloud Armor, a system that detects and blocks the tampering of user commands without the need for modifications to cloud services. Our insight is that we can construct state machine models to limit the system call sequences executed by cloud services. By applying constraints over system call arguments, we can restrict the way user commands are executed, blocking unauthorized operations from compromised cloud services. We implemented a prototype Cloud Armor system for Open Stack, a widely adopted open source cloud platform. Results show that Cloud Armor can greatly limit attack options available for adversaries while imposing less than 1% overhead for user VMs. As a result, cloud users can leverage Cloud Armor to execute user commands safely even in presence of compromised cloud services.
DOI: 10.1145/1294261.1294279
发表时间: 2007-10
期刊: --
影响因子: --
作者:
Andreas Haeberlen;P. Kuznetsov;P. Druschel
通讯作者: Andreas Haeberlen;P. Kuznetsov;P. Druschel