课题基金 / 基金详情

CAREER: Infrastructure for Secure Cloud Computing

CAREER: Infrastructure for Secure Cloud Computing
职业:安全云计算基础设施
批准号:
1253870
负责人:
Thomas Ristenpart
金额:
$48.06万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2013
资助国家:
美国
项目状态:
已结题
起止时间:
2013-06-01 至 2015-10-31

项目摘要

项目成果

Thomas Ristenpart的其他基金

相似基金

相关文献

中文摘要
翻译
基础设施即服务(IaaS)云计算系统通过提供对可扩展计算的方便访问,正在彻底改变商业、政府和科学。这些公共服务(由Amazon、b谷歌、Microsoft和其他公司提供)允许任意客户按小时租用所需资源,以便在托管在提供商上的虚拟机(vm)中运行其应用程序。S计算基础设施。然而,这些新服务带来了微妙的新安全问题。PI先前的工作发现,攻击滥用了云计算独有的两个方面:相互不信任的客户之间的资源共享和激励恶意行为的定价。本文的研究主要围绕资源共享和定价两个主题展开。在第一个主题中,研究工作探讨了加密侧信道攻击和资源释放攻击是否对云客户构成严重威胁,然后开发了新的放置和CPU调度算法,实现了软隔离的安全原则:最大限度地减少潜在危险的跨用户调度交互(例如,共享服务器或CPU核心)。在第二个主题中,该工作探讨了细粒度定价机制对安全性的影响。这包括开发价格标记(准确确定云服务真实成本的机制),理解利用云性能异质性的客户控制放置游戏,并探索基于价格的安全机制,与上述调度机制相结合,将降低对抗性行为的财政激励。拟议工作的影响将是更深入地了解云IaaS系统中的威胁、新的安全设计原则、可部署的安全技术以及安全教育的改进。
英文摘要
Infrastructure-as-a-service (IaaS) cloud computing systems are revolutionizing business, government, and science by providing easy access to scalable computing. These public services, as offered by Amazon, Google, Microsoft, and others, allow an arbitrary customer to rent, by the hour, the resources needed to run their applications within virtual machines (VMs) hosted on the provider?s compute infrastructure. With these new services, however, comes subtle new security issues. Prior work by the PI uncovered attacks that abuse two aspects unique to cloud computing: resource sharing among mutually distrustful customers and pricing that incentivizes malicious behavior. The proposed research is organized along the two themes of resource sharing and pricing. In the first theme, the work explores whether cryptographic side channel attacks and resource-freeing attacks pose serious threats to cloud customers and then develops new placement and CPU scheduling algorithms that realize the security principle of soft isolation: minimization of potentially dangerous cross-user scheduling interactions (e.g., sharing a server or CPU core). Within the second theme, the work explores the implications of fine-grained pricing mechanisms on security. This includes developing pricemarks (mechanisms for accurately determining the true costs of a cloud service), understanding customer-controlled placement gaming that exploits cloud performance heterogeneity, and explores pricing-based security mechanisms that, in conjunction with the aforementioned scheduling mechanisms, will degrade fiscal incentivizes for adversarial behavior. The impact of the proposed work will be deeper understanding of threats in cloud IaaS systems, new security design principles, deployable security technologies, and improvements in security education.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Large: Privacy-Preserving Abuse Prevention for Encrypted Communications Platforms
  • 批准号:
    2120651
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $262.82万
  • 财政年份:
    2021
  • 负责人:
    Thomas Ristenpart
  • 依托单位:
Collaborative Research: SaTC: CORE: Medium: Mixed Distribution Models for Encrypted Data Stores
  • 批准号:
    2055169
  • 项目类别:
    Standard Grant
  • 资助金额:
    $66.67万
  • 财政年份:
    2021
  • 负责人:
    Thomas Ristenpart
  • 依托单位:
CAREER: Infrastructure for Secure Cloud Computing
  • 批准号:
    1558500
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $38.52万
  • 财政年份:
    2015
  • 负责人:
    Thomas Ristenpart
  • 依托单位:
海外基金