• Cite Icon89
  • https://doi.org/10.1145/2590296.2590300Copy DOI Icon

After we knew it

  • Jun 4, 2014
  • Su Zhang +2 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Infrastructure as a Service (IaaS) cloud has been attracting more and more customers as it provides the highest level of flexibility by offering configurable virtual machines (VMs) and computing infrastructures. Public VM images are usually available for customers to customize and launch. However, the 1 to N mapping between VM images and running instances in IaaS makes vulnerabilities propagate rapidly across the entire public cloud. Besides, IaaS cloud naturally comes with a larger and more stable attack surface and more concentrated target resources than traditional surroundings. In this paper, we first identify the threat of exploiting prevalent vulnerabilities over public IaaS cloud with an empirical study in Amazon EC2. We find that attackers can compromise a considerable number of VMs with trivial cost. We then do a qualitative cost-effectiveness analysis of this threat. Our main result is a two-fold observation: in IaaS cloud, exploiting prevalent vulnerabilities is much more cost-effective than traditional in-house computing environment, therefore attackers have stronger incentive; Fortunately, on the other hand, cloud defenders (cloud providers and customers) also have much lower cost-loss ratio than in traditional environment, therefore they can be more effective for defending attacks. We then build a game-theoretic model and conduct a risk-gain analysis to compare exploiting and patching strategies under cloud and traditional computing environments. Our modeling indicates that under cloud environment, both attack and defense become less cost-effective as time goes by, and the earlier actioner can be more rewarding. We propose countermeasures against such threat in order to bridge the gap between current security situation and defending mechanisms. To our best knowledge, we are the first to analyze and model the threat with prevalent known-vulnerabilities in public cloud.

Similar Papers
  • Conference Article
  • Citations3

VMBeam: Zero-Copy Migration of Virtual Machines for Virtual IaaS Clouds

  • Sep 01, 2016
  • Kenichi Kourai +1
  • Research Article
  • Citations19

Allocating Bandwidth in Datacenter Networks: A Survey

  • Sep 01, 2014
  • Journal of Computer Science and Technology
  • Li Chen +2
  • Research Article
  • Citations1

An overview of CMPI

  • Feb 25, 2012
  • ACM SIGPLAN Notices
  • Yifan Gong +2
  • Conference Article

Fast VM Startup by Cooperative Image Caching for Cloud Data Centers

  • Oct 01, 2018
  • Yifan Zhang +3
  • Conference Article
  • Citations3

Semantics-Aware Virtual Machine Image Management in IaaS Clouds

  • May 01, 2019
  • Nishant Saurabh +4
  • Research Article
  • Citations6

Cost Evaluation on Building and Operating Cloud Platform

  • Apr 01, 2013
  • International Journal of Grid and High Performance Computing
  • Yue-Shan Chang +3
  • Research Article
  • Citations20

Self-adaptive architecture for virtual machines consolidation based on probabilistic model evaluation of data centers in Cloud computing

  • Jun 06, 2018
  • Cluster Computing
  • Reza Mohammadi Bahram Abadi +2
  • Conference Article
  • Citations6

EMinRET: Heuristic for Energy-Aware VM Placement with Fixed Intervals and Non-preemption

  • Nov 01, 2015
  • Nguyen Quang-Hung +1
  • Research Article
  • Citations2

Efficient and Fine-Grained VMM-Level Packet Filtering for Self-Protection

  • Apr 01, 2014
  • International Journal of Adaptive, Resilient and Autonomic Systems
  • Kenichi Kourai +2
  • Conference Article

Diagnosing Memory Provisioning in IaaS Clouds

  • Nov 01, 2013
  • Ricardo J Pfitscher +2
  • Research Article
  • Citations3

Experience in Practical Implementation of Abstraction Interface for Integrated Cloud Resource Management on Multi-Clouds

  • Jan 31, 2016
  • KSII Transactions on Internet and Information Systems
  • Huioon Kim +3
  • Research Article
  • Citations13

A batch system for HEP applications on a distributed IaaS cloud

  • Dec 23, 2011
  • Journal of Physics: Conference Series
  • I Gable +12
  • Research Article

ENTICE VM Image Analysis and Optimised Fragmentation

  • Feb 21, 2018
  • Journal of Grid Computing
  • Akos Hajnal +5
  • Conference Article
  • Citations3

Fine-Grained, Adaptive Resource Sharing for Real Pay-Per-Use Pricing in Clouds

  • Sep 01, 2015
  • Young Choon Lee +3
  • Book Chapter
  • Citations3

A New Cloud Computing Deployment Model: Proprietary Cloud

  • Jan 01, 2023
  • Weibo Zhao +4
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.