Purgemem: Towards Building A Memory Safe Cloud

2019 IEEE SOUTHEASTCON(2019)

引用 0|浏览15
暂无评分
摘要
Cloud computing has become the industry standard for rapid application deployment, scalable server support, and mobile and distributed services. It provides seamless scalability and access to infinite resource theoretically. Unfortunately, the co-tenancy of cloud computing makes Cloud Services vulnerable to privacy issues. In the past, researchers have shown that it is possible to compromise important information by exploiting the co-tenancy nature of clouds. In this paper, we first identify a new method which can be used to collect residual application data from the main memory of a virtual machine hosted in the cloud even the application is closed by the user. We show that using traditional forensic tools in all three major cloud providers (Amazon AWS, Google Cloud, and Microsoft Azure), one can gather information about a closed application from the main memory if the machine is compromised. To resolve this vulnerability, we propose PurgeMEM, a framework which provides a service 14 deleting residual memory left by a closed application. PurgeMEM continuously monitors processes launched by user applications. When a process is about to finish, PurgeMEM is notified and then it cleans up the physical memory location by writing known hex values and thereby preserving the privacy of the user data. We developed a PurgeMEM prototype for the Linux environment and evaluated it with four small applications. For all the applications, our prototype is able to sanitize and delete memory residuals successfully with a negligible performance overhead (2.97%).
更多
查看译文
关键词
physical memory location,user data,PurgeMEM prototype,memory residuals,cloud computing,industry standard,rapid application deployment,scalable server support,mobile distributed services,seamless scalability,privacy issues,cloud services,residual application data,virtual machine,forensic tools,cloud providers,Google Cloud,closed application,residual memory,memory safe cloud
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要