信息网络安全 ›› 2020, Vol. 20 ›› Issue (8): 55-61.doi: 10.3969/j.issn.1671-1122.2020.08.007

• 技术研究 • 上一篇    下一篇

云环境中基于分组的安全虚拟机放置方法

陈婉莹, 王运鹏(), 赵珂雨, 刘晓洁   

  1. 四川大学网络空间安全学院,成都 610041
  • 收稿日期:2020-05-15 出版日期:2020-08-10 发布日期:2020-10-20
  • 通讯作者: 王运鹏 E-mail:haocwy@126.com
  • 作者简介:陈婉莹(1996—),女,四川,硕士研究生,主要研究方向为云计算|王运鹏(1984—),男,四川,博士研究生,主要研究方向为信息安全、区块链|赵珂雨(1996—),女,四川,硕士研究生,主要研究方向为计算机网络与信息安全|刘晓洁(1965—),女,江苏,教授,硕士,主要研究方向为网络信息对抗与保护技术、数字虚拟资产保护技术。
  • 基金资助:
    国家自然科学基金(U1736212);国家自然科学基金(U19A2068);四川省重点研发项目(2018GZ0183);四川省重点研发项目(20ZDYF3145)

Secure Virtual Machine Placement Method Based on Grouping in Cloud Environment

CHEN Wanying, WANG Yunpeng(), ZHAO Keyu, LIU Xiaojie   

  1. College of Cybersecurity, Sichuan University, Chengdu 610041, China
  • Received:2020-05-15 Online:2020-08-10 Published:2020-10-20
  • Contact: WANG Yunpeng E-mail:haocwy@126.com

摘要:

在云环境中,通常将不同用户的虚拟机放置在同一台物理机上,这种物理资源的共享对用户的隐私数据构成了严重威胁。恶意用户可以通过启动大量虚拟机或者利用虚拟机放置策略存在的漏洞提高与目标虚拟机共存的概率。为了进行主动防御,文章提出一种在考虑安全性的同时也关注能耗以及负载均衡的放置方法。将虚拟机以相同的概率进行随机分组,以防止恶意用户获取并利用虚拟机在放置位置上表现出的特征;为了减小恶意用户通过启动过多虚拟机以增大与目标虚拟机共存的概率,当某个用户的虚拟机分配的组数超过阈值后,将不被分配新的组;综合考虑能耗和负载均衡的情况,将其分配到合适的物理机上。实验结果表明,文章在考虑负载和能耗的基础上,减少了不同用户虚拟机之间共存的概率,增强了虚拟机放置的安全性。

关键词: 放置策略, 虚拟机分组, 云环境, 共存攻击

Abstract:

In the cloud environment, virtual machines of different users are usually placed on the same physical machine, and this sharing of physical resources poses a serious threat to users' private data. Malicious users can improve the probability of co-existence with the target virtual machine by starting a large number of virtual machines or by taking advantage of the loopholes in the virtual machine placement strategy. In order to defend it actively, a placement method which considers the safety, energy consumption and load balance is proposed. First will be randomly assigned a virtual machine with the same probability, in order to prevent malicious users to obtain and make use of the virtual machine in place of some of the characteristics, in order to reduce the malicious user too much by starting the virtual machine to increase the probability of coexistence with the target virtual machine, the virtual machine when a user is assigned to the group number exceeds a certain value, will be assigned to the new group. Then, considering the situation of energy consumption and load balance, it is allocated to the appropriate physical host. The experimental results show that the probability of co-existence between virtual machines of different users is reduced and the security of virtual machine placement is guaranteed to a certain extent.

Key words: placement policy, virtual machine grouping, cloud environment, co-existence attack

中图分类号: