4.7 Article

Co-residence based data vulnerability vs. security in cloud computing system with random server assignment

期刊

EUROPEAN JOURNAL OF OPERATIONAL RESEARCH
卷 267, 期 2, 页码 676-686

出版社

ELSEVIER
DOI: 10.1016/j.ejor.2017.11.064

关键词

Cloud computing; Co-residence attack; Data partition; Data theft; Data corruption

资金

  1. National Natural Science Foundation of China [61170042]
  2. Jiangsu province development and reform commission [2013-883]

向作者/读者索取更多资源

The virtualization technology, particularly virtual machines (VMs) used in cloud computing systems have raised unique security and survivability risks for cloud users. This paper focuses on one of such risks, co-residence attacks where a user's information in one VM can be accessed (stolen) or corrupted through side channels by a malicious attacker's VM co-residing on the same server. We model and optimize users' data protection policy in which sensitive data are partitioned into several blocks to enhance data security and multiple replicas are further created for each block to provide data survivability in a cloud environment subject to the co-residence attacks. Both users' and attackers' VMs are distributed among cloud servers at random. Probabilistic models are first suggested to derive the overall probabilities of an attacker's success in data theft and data corruption. Based on the suggested probabilistic evaluation models, optimization problems of obtaining the data partition/replication policy to balance data security, data survivability and a user's overheads are formulated and solved. The possible user's uncertainty about the number of attacker's VMs is taken into account. Numerical examples demonstrating influence of different constraints on the optimal policy are presented. (C) 2017 Elsevier B.V. All rights reserved.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.7
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据