High performance and security in cloud computing

Kai Bu, Bin Xiao, Yi Qian · Concurrency and Computation Practice and Experience · 2017

"Cloud" is a common metaphor for an Internet accessible infrastructure (e.g., data storage and computing hardware) that is hidden from users. Cloud computing makes data truly mobile and a user can simply access a chosen cloud with any internet accessible device. In cloud computing, IT-related capabilities are provided as services, accessible without requiring detailed knowledge of the underlying technology. Thus, many mature technologies are used as components in cloud computing, but still there are many unresolved and open problems. This special issue includes articles addressing the state-of-the-art in strengthening performance and security and cloud computing. Eight representative research articles were carefully selected based on the original presentations at the 2016 International Conference on Cloud Computing and Big Data (CloudCom-Asia'16). The objective of this conference is to bring together researchers who work on cloud computing and related technologies. According to whether its research theme relates more to performance or security, the accepted papers are briefly described in the remaining part of this section. Task scheduling is critical for guaranteeing cloud performance. In the past years, more and more business-to-consumer and enterprise applications start running in the heterogeneous cloud. Such cloud bag-of-tasks (BoT) applications are usually budget-constrained and their scheduling is an essential problem for cloud provider. The problem is even more complex and challenging when the accurate knowledge about task execution time is unknown in advance. Focusing on these challenges, Tang et al1 build a cloud resource management architecture and stochastic task model, which divides cloud task into two execution parts. Then they deduce BoT applications schedule length and total cost according to heterogenous clouds online feedback information. They further formulate this stochastic scheduling problem as a linear programming problem and propose a time and cost multi-objective stochastic task scheduling genetic algorithm, which can find Pareto-optimal schedules for stochastic cloud task that meet its budget constraint. With the rapid development of Internet and cloud computing, the high performance requirements for data center networks (DCNs) are increasing for meeting the need of users. A large number of data need to be processed and shared among servers in a data center. Recently, multicast traffic in DCNs has attracted much attention from academia due to the fact that multicast traffics have the dominating advantages for group communications in DCNs. Therefore, the appropriate multicast traffic scheduling in data center networks cannot only improve network efficiency but also save network resources. Li et al2 propose a multicast scheduling algorithm to appropriately schedule flows to achieve traffic load balance so that network blocking can be avoided. In order to reduce the network blocking, they propose an efficient blocking cost-driven multicast scheduling algorithm in fat-tree DCNs. The paper establishes the blocking model of multicast network based on multicast network state and presents the blocking probability at the next time-slot, which can reduce the scheduling delay of multicast traffic. Furthermore, the paper presents also an optimal selection mechanism of feasible links based on the given link blocking probability at the next time-slot. In order to study cloud performance from a more comprehensive perspective, Wang et al3 investigate how to decide key parameters in service-oriented cloud computing systems to improve the system's performance and maximize the service provider's profit. The paper proposes a multiple game model to formulate the critical parameters decision process. For games among different participators, different rules are used to estimate corresponding key parameters. The proposed MG model can achieve Pareto-optimal equilibrium point, and its efficiency in dynamically deciding key parameters in CCSs are demonstrated by simulation results. Underlying infrastructure plays also a vital role for cloud performance. Newly emerging networking paradigms like Software-Defined Networking (SDN) promises more advances like flexibility and efficiency to cloud management. He et al4 propose NetCore-M language, a high abstraction level programming language for SDN. It can support for packet drop and conflicts detection. NetCore-M language provides a more abstract programming language for network configuration in data center. Specifically, the paper describes in detail the syntax, semanteme, and implementation of NetCore-M language as well as network policy conflict. Besides, this paper verifies that the modified multi-policies combination algorithm can effectively detect policy conflicts based on the implementation of the Pyretic project. Security of applications in multi-cloud collaborative environments is a major concern in today's distributed computing environment. Multi-cloud collaborative environments are highly heterogeneous. The security issues in such environments most commonly arise due to the use of ineffective access control mechanisms. The primary goal of Attribute-based Access Control (ABAC) as an access control model is to fulfill the requirements of highly heterogeneous environments such as multi-cloud environment. There are two major challenges for a system employing ABAC. The first is to determine suitable attributes for users and resources in the system. Formation of the correct set of ABAC rules is another major challenge. John et al5 investigate the development of two alternative approaches for deriving the minimum number of ABAC rules in a multi-cloud environment. In the first approach, they consider forming a minimal set of positive authorizations only. The second approach shows the advantage of developing negative authorizations along with positive authorizations. Together, these two contributions extend the current state-of-the-art in cloud security. With the advent of cloud computing, more and more consumers prefer to use the cloud services with the pay-as-you-consume mode. The cloud storage brings about great convenience to users, who store data in cloud and access to it using the smart devices anytime and anywhere. Consumers' information should be encrypted to guarantee the data privacy. Flexible searching on ciphertext is a critical challenge to be solved for effective data utilization. Yang et al6 propose a novel semantic keyword searchable proxy re-encryption scheme for secure cloud storage. The scheme is quantum attack resistant, while most of the available searchable encryption schemes are not. It not only supports exact keyword search, but also synonym keyword search. Moreover, the data owner is capable to delegate his search right to another user using the proxy re-encryption mechanism. In the generation process of re-encryption key, the delegator and delegate do not need to interactive with each other. The scheme is also collusion resistant. Under the learning with errors hardness problem, this scheme is proved secure in standard model. Wu et al7 investigates how to prohibit massive Twitter spams from cloud. This paper leveraged the massive posts information from social network platforms especially Twitter. Learning from millions of text-based tweets (Twitter messages), algorithms were generated to detect social spammers who propagate suspicious information. The authors developed an innovative spam detection method in Twitter using deep learning techniques, which may contribute to the field in terms of protecting cyber security. They put forward a new Twitter spam detection method based on deep learning to address the problems of existing methods. A series of empirical and theoretical analysis have been adopted to prove the outperformance of the proposed method. These studies will contribute to future analysis and optimization on Twitter spam detection. Meanwhile, more and more client applications for cloud are based on mobile devices. Thus, the security of mobile operating systems is crucial for securing the cloud applications. Qiang et al8 embark on solving the covert channel issues in smartphone operating systems, which may lead to furtive data transmission between applications with different permissions that might threaten users' privacy. The authors propose a general method that can detect covert channel attacks at runtime without impacting the accessibility of shared resources in the system. The method allows users to describe and audit the target covert channels in the application layer as well as the OS layer, by making use of Java hooks and kernel audit tool auditd. The main idea of the method is to track and audit the use of system resources known as potential covert channel variables and impose interferences on those channels to reduce their capacity once violations are detected. They implement a prototype framework to audit and interfere covert communication in both the application layer and the native layer of Android. The experimental results demonstrate that the proposed method can effectively reduce the data rate of user-defined covert channels while the overhead is negligible. The papers presented in this special issue provide research articles related to recent advances in cloud computing. In particular, these research articles aim to strengthen cloud performance and security, from various aspects including task scheduling and underlying SDN infrastructure. We hope that the readers of this special issue will benefit from the research ideas and concepts presented in these research articles. The guest editors of this special issue would like to express their special thanks to all of the authors who submitted their papers to this special issue and to all reviewers who contribute to the paper selection process. We would also like to deeply thank Professor Geoffrey C. Fox, the Editor-in-Chief, for providing the opportunity to publish this special issue and for offering continuous support, encouragement, and guidance throughout this publishing project.

Read the paper · More papers on PaperTik