Matches in SemOpenAlex for { <https://semopenalex.org/work/W2400179508> ?p ?o ?g. }
Showing items 1 to 83 of
83
with 100 items per page.
- W2400179508 abstract "Infrastructure-as-a-Service (IaaS) clouds such as OpenStack consist of two kinds of nodes in their infrastructure: control nodes and compute nodes. While control nodes run all critical services, compute nodes host virtual machines of customers. Given the large number of compute nodes, and the fact that they are hosting VMs of (possibly malicious) customers, it is possible that some of the compute nodes may be compromised. This paper examines the impact of such a compromise. We focus on OpenStack, a popular open-source cloud plat- form that is widely adopted. We show that attackers com- promising a single compute node can extend their controls over the entire cloud infrastructure. They can then gain free access to resources that they have not paid for, or even bring down the whole cloud to affect all customers. This startling result stems from the cloud platform's misplaced trust, which does not match today's threats. To overcome the weakness, we propose a new system, called SOS , for hardening OpenStack. SOS limits trust on compute nodes. SOS consists of a framework that can enforce a wide range of security policies. Specifically, we applied mandatory access control and capabilities to con- fine interactions among different components. Effective confinement policies are generated automatically. Furthermore, SOS requires no modifications to the OpenStack. This has allowed us to deploy SOS on multiple versions of OpenStack. Our experimental results demonstrate that SOS is scalable, incurs negligible overheads and offers strong protection." @default.
- W2400179508 created "2016-06-24" @default.
- W2400179508 creator A5028680353 @default.
- W2400179508 creator A5042516416 @default.
- W2400179508 creator A5082264643 @default.
- W2400179508 date "2016-05-30" @default.
- W2400179508 modified "2023-10-10" @default.
- W2400179508 title "Hardening OpenStack Cloud Platforms against Compute Node Compromises" @default.
- W2400179508 cites W180396117 @default.
- W2400179508 cites W1992291252 @default.
- W2400179508 cites W2004460663 @default.
- W2400179508 cites W2048855209 @default.
- W2400179508 cites W2056073317 @default.
- W2400179508 cites W2077101621 @default.
- W2400179508 cites W2116272682 @default.
- W2400179508 cites W2119028650 @default.
- W2400179508 cites W2122266630 @default.
- W2400179508 cites W2133718106 @default.
- W2400179508 cites W2135143063 @default.
- W2400179508 cites W2160892968 @default.
- W2400179508 cites W2167088175 @default.
- W2400179508 cites W2169461225 @default.
- W2400179508 cites W2169965429 @default.
- W2400179508 cites W78987640 @default.
- W2400179508 doi "https://doi.org/10.1145/2897845.2897851" @default.
- W2400179508 hasPublicationYear "2016" @default.
- W2400179508 type Work @default.
- W2400179508 sameAs 2400179508 @default.
- W2400179508 citedByCount "15" @default.
- W2400179508 countsByYear W24001795082016 @default.
- W2400179508 countsByYear W24001795082017 @default.
- W2400179508 countsByYear W24001795082018 @default.
- W2400179508 countsByYear W24001795082019 @default.
- W2400179508 countsByYear W24001795082020 @default.
- W2400179508 crossrefType "proceedings-article" @default.
- W2400179508 hasAuthorship W2400179508A5028680353 @default.
- W2400179508 hasAuthorship W2400179508A5042516416 @default.
- W2400179508 hasAuthorship W2400179508A5082264643 @default.
- W2400179508 hasConcept C111919701 @default.
- W2400179508 hasConcept C120314980 @default.
- W2400179508 hasConcept C127413603 @default.
- W2400179508 hasConcept C25344961 @default.
- W2400179508 hasConcept C31258907 @default.
- W2400179508 hasConcept C38652104 @default.
- W2400179508 hasConcept C41008148 @default.
- W2400179508 hasConcept C48044578 @default.
- W2400179508 hasConcept C513985346 @default.
- W2400179508 hasConcept C527821871 @default.
- W2400179508 hasConcept C62611344 @default.
- W2400179508 hasConcept C66938386 @default.
- W2400179508 hasConcept C79974875 @default.
- W2400179508 hasConcept C93996380 @default.
- W2400179508 hasConceptScore W2400179508C111919701 @default.
- W2400179508 hasConceptScore W2400179508C120314980 @default.
- W2400179508 hasConceptScore W2400179508C127413603 @default.
- W2400179508 hasConceptScore W2400179508C25344961 @default.
- W2400179508 hasConceptScore W2400179508C31258907 @default.
- W2400179508 hasConceptScore W2400179508C38652104 @default.
- W2400179508 hasConceptScore W2400179508C41008148 @default.
- W2400179508 hasConceptScore W2400179508C48044578 @default.
- W2400179508 hasConceptScore W2400179508C513985346 @default.
- W2400179508 hasConceptScore W2400179508C527821871 @default.
- W2400179508 hasConceptScore W2400179508C62611344 @default.
- W2400179508 hasConceptScore W2400179508C66938386 @default.
- W2400179508 hasConceptScore W2400179508C79974875 @default.
- W2400179508 hasConceptScore W2400179508C93996380 @default.
- W2400179508 hasLocation W24001795081 @default.
- W2400179508 hasOpenAccess W2400179508 @default.
- W2400179508 hasPrimaryLocation W24001795081 @default.
- W2400179508 hasRelatedWork W1963799338 @default.
- W2400179508 hasRelatedWork W2036412865 @default.
- W2400179508 hasRelatedWork W2088620127 @default.
- W2400179508 hasRelatedWork W2542775576 @default.
- W2400179508 hasRelatedWork W2545334782 @default.
- W2400179508 hasRelatedWork W2558538437 @default.
- W2400179508 hasRelatedWork W2612791064 @default.
- W2400179508 hasRelatedWork W2743348030 @default.
- W2400179508 hasRelatedWork W2900408237 @default.
- W2400179508 hasRelatedWork W2947629119 @default.
- W2400179508 isParatext "false" @default.
- W2400179508 isRetracted "false" @default.
- W2400179508 magId "2400179508" @default.
- W2400179508 workType "article" @default.