A State-Based Proactive Approach To Network Isolation Verification In Clouds


Chawla, Gagandeep Singh ORCID: https://orcid.org/0000-0002-8076-3328 (2019) A State-Based Proactive Approach To Network Isolation Verification In Clouds. Masters thesis, Concordia University.

The multi-tenancy nature of public clouds usually leads to cloud tenants' concerns over network isolation around their virtual resources. Verifying network isolation in clouds faces unique challenges. The sheer size of virtual infrastructures paired with the self-serviced nature of clouds means the verification will likely have a high complexity and yet its results may become obsolete in seconds. Moreover, the _ne-grained and distributed network access control (e.g., per-VM security group rules) typical to virtual cloud infrastructures means the verification must examine not only the events but also the current state of the infrastructures. In this thesis, we propose VMGuard, a state-based proactive approach for efficiently verifying large-scale virtual infrastructures against network isolation policies. Informally, our key idea is to proactively trigger the verification based on predicted events and their simulated impact upon the current state, such that we can have the best of both worlds, i.e., the efficiency of a proactive approach and the effectiveness of state-based verification. We implement and evaluate VMGuard based on OpenStack, and our experiments with both real and synthetic data demonstrate the performance and efficiency.

Divisions:Concordia University > Gina Cody School of Engineering and Computer Science
Item Type:Thesis (Masters)
Authors:Chawla, Gagandeep Singh
Institution:Concordia University
Degree Name:M.A. Sc.
Program:Information Systems Security
Date:21 August 2019
Thesis Supervisor(s):Wang, Lingyu
Keywords:Security Compliance Verification Cloud Security Security Auditing Network Isolation
ID Code:985764
Deposited By: Gagandeep Singh Chawla
Deposited On:05 Feb 2020 14:23
Last Modified:06 Feb 2020 01:00


