CryptVMI: Encrypted virtual machine introspection in the cloud

Fangzhou Yao, R H Campbell

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Virtualization techniques are the key in both public and private cloud computing environments. In such environments, multiple virtual instances are running on the same physical machine. The logical isolation between systems makes security assurance weaker than physically isolated systems. Thus, Virtual Machine Introspection techniques become essential to prevent the virtual system from being vulnerable to attacks. However, this technique breaks down the borders of the segregation between multiple tenants, which should be avoided in a public cloud computing environment. In this paper, we focus on building an encrypted Virtual Machine Introspection system, CryptVMI, to address the above concern, especially in a public cloud system. Our approach maintains a query handler on the management node to handle encrypted queries from user clients. We pass the query to the corresponding compute node that holds the virtual instance queried. The introspection application deployed on the compute node processes the query and acquires the encrypted results from the virtual instance for the user. This work shows our design and preliminary implementation of this system.

Original languageEnglish (US)
Title of host publicationProceedings - 2014 IEEE 7th International Conference on Cloud Computing, CLOUD 2014
EditorsCarl Kesselman
PublisherIEEE Computer Society
Pages977-978
Number of pages2
ISBN (Electronic)9781479950638
DOIs
StatePublished - Dec 3 2014
Event7th IEEE International Conference on Cloud Computing, CLOUD 2014 - Anchorage, United States
Duration: Jun 27 2014Jul 2 2014

Publication series

NameIEEE International Conference on Cloud Computing, CLOUD
ISSN (Print)2159-6182
ISSN (Electronic)2159-6190

Other

Other7th IEEE International Conference on Cloud Computing, CLOUD 2014
CountryUnited States
CityAnchorage
Period6/27/147/2/14

    Fingerprint

ASJC Scopus subject areas

  • Artificial Intelligence
  • Information Systems
  • Software

Cite this

Yao, F., & Campbell, R. H. (2014). CryptVMI: Encrypted virtual machine introspection in the cloud. In C. Kesselman (Ed.), Proceedings - 2014 IEEE 7th International Conference on Cloud Computing, CLOUD 2014 (pp. 977-978). [6973855] (IEEE International Conference on Cloud Computing, CLOUD). IEEE Computer Society. https://doi.org/10.1109/CLOUD.2014.149