A Game-Theoretic Framework for the Virtual Machines Migration Timing Problem

A Game-Theoretic Framework for the Virtual Machines Migration Timing Problem
复制标题

DOI:
10.1109/tcc.2019.2905605
复制
发表时间:
2018-03
影响因子:
6.5
通讯作者:
Ahmed H. Anwar;George K. Atia;Mina Guirguis
Ahmed H. Anwar;George K. Atia;Mina Guirguis
中科院分区:
计算机科学2区
文献类型:
--
作者:
Ahmed H. Anwar;George K. Atia;Mina Guirguis

文献摘要

相似文献

在多租户云中,多个虚拟机(vm)被配置在同一台物理机上,以优化性能、降低功耗并实现利润最大化。但是,这增加了恶意虚拟机进行侧通道攻击和泄露相邻虚拟机敏感信息的风险。因此,本文开发并分析了虚拟机迁移时间问题的博弈论框架,在该框架中,云提供商决定何时将虚拟机迁移到不同的物理机,以降低被并置的恶意虚拟机损害的风险。攻击者决定她启动新vm的速率,以便与受害者vm进行配置。我们的公式捕获了一个数据泄漏模型,其中云提供商产生的成本取决于与恶意虚拟机搭配的持续时间。它还捕获攻击者在启动新vm和防御者在迁移vm时产生的成本。我们建立了一般成本函数存在纳什均衡的充分条件,以及具体实例,并描述了双方参与者的最佳对策。此外,我们扩展了我们的模型,以描述当云利用检测侧信道攻击的入侵检测系统时,它对攻击者收益的影响。我们的理论发现与各种设置中的广泛数值结果以及现实云设置中的概念验证实施相证实。
In a multi-tenant cloud, a number of Virtual Machines (VMs) are collocated on the same physical machine to optimize performance, power consumption and maximize profit. This, however, increases the risk of a malicious VM performing side-channel attacks and leaking sensitive information from neighboring VMs. As such, this paper develops and analyzes a game-theoretic framework for the VM migration timing problem in which the cloud provider decides when to migrate a VM to a different physical machine to reduce the risk of being compromised by a collocated malicious VM. The adversary decides the rate at which she launches new VMs to collocate with the victim VMs. Our formulation captures a data leakage model in which the cost incurred by the cloud provider depends on the duration of collocation with malicious VMs. It also captures costs incurred by the adversary in launching new VMs and by the defender in migrating VMs. We establish sufficient conditions for the existence of Nash equilibria for general cost functions, as well as for specific instantiations, and characterize the best response for both players. Furthermore, we extend our model to characterize its impact on the attacker’s payoff when the cloud utilizes intrusion detection systems that detect side-channel attacks. Our theoretical findings are corroborated with extensive numerical results in various settings as well as a proof-of-concept implementation in a realistic cloud setting.