Advocating isolation of resources among multi-tenants by containerization in IaaS cloud model

Javed Ahmed Samo, Zeeshan Ahmed, Aasia Shaikh · 2017

Cloud Computing refers to the dynamic provisioning of resources to multiple tenants around the globe to process big volumes of data at high speed, remotely from any instance. It caters the multiple needs of users like storing huge variety of data, providing interfaces and environments to work collaboratively on projects using Platform as service model, failover server and disaster recovery of datacenter servers and many more. The technology also offers a major advantage by providing a multi-tenancy of physical infrastructures, platforms, applications or combination by the help of virtualization techniques like virtual machine managers/hypervisors and container. Both these techniques have few grey areas. The most vulnerable threat is “co-residence of multi-tenants/ virtual machines on same physical resources”. In this paper we performed experiments to assess security of both containers and hypervisors. We used Hyper-V as VMM and Docker as container. The experiments were performed to measure the vulnerabilities parameters such as side channel attack. The results suggest that Hypervisor lacks sufficient logical isolation configuration that a suspicious can attacks or peeks other VMs by side channel attack and causes security flaws among multi-tenants to compromise the confidentiality and integrity of data. On the other hand container is much more secure and provides much stronger isolation at micro level in terms of resources and overcome the issues raised in VMM among multiple tenants.

Read the paper · More papers on PaperTik