Title
Scalable Cloud Security via Asynchronous Virtual Machine Introspection.
Abstract
Software will always be vulnerable to attacks. Although techniques exist that could prevent or limit the risk of exploits, performance overhead blocks their adoption. Services deployed into the cloud are typically customer facing, leaving them even more exposed to attacks from malicious users. However, the use of virtual machines, and the economy of scale found in cloud platforms, provides an opportunity to offer strong security guarantees to tenants at low cost to the cloud provider. We present ScaaS, a security Scanning as a Service framework for cloud platforms that uses frequent virtual machine checkpointing coupled with memory introspection techniques to detect bugs and malicious behavior in real time. By buffering VM outputs (i.e., outgoing network packets and disk writes) until a scan has been completed, ScaaS gives strong guarantees about the amount of damage an attack can do, while minimizing overheads.
Year
Venue
Field
2016
HotCloud
Asynchronous communication,Virtual machine,Computer security,Computer science,Network packet,Real-time computing,Exploit,Cloud computing security,Software,Scalability,Cloud computing,Distributed computing
DocType
Citations 
PageRank 
Conference
2
0.37
References 
Authors
7
6
Name
Order
Citations
PageRank
Sundaresan Rajasekaran1462.85
Zhen Ni221.72
Harpreet Singh Chawla320.37
Neel Shah441.86
Timothy Wood534927.52
Emery D. Berger6104855.87