Security-aware dynamic VM consolidation
The explosive growth of cloud usage encourages several challenges, especially high energy consumption of Cloud Data Centers (CDCs), new security risks to Virtual Machines (VMs) resulting from co-residency with other risky VMs on the same Physical Machine (PM), and the Quality of Service (QoS) degrad...
Main Authors: | , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
Elsevier
2021-09-01
|
Series: | Egyptian Informatics Journal |
Subjects: | |
Online Access: | http://www.sciencedirect.com/science/article/pii/S1110866520301572 |
id |
doaj-3e89206fe02d47419fb13ef8c0002bfd |
---|---|
record_format |
Article |
spelling |
doaj-3e89206fe02d47419fb13ef8c0002bfd2021-09-19T04:55:11ZengElsevierEgyptian Informatics Journal1110-86652021-09-01223277284Security-aware dynamic VM consolidationMohamed A. Elshabka0Hanan A. Hassan1Walaa M. Sheta2Hany M. Harb3Informatics Research Institute, City of Scientific Research and Technological Applications (SRTA-CITY), Alexandria, Egypt; Corresponding author at: Informatics Research Institute, City of Scientific Research and Technological Applications (SRTA-CITY), Alexandria, Egypt.Informatics Research Institute, City of Scientific Research and Technological Applications (SRTA-CITY), Alexandria, EgyptInformatics Research Institute, City of Scientific Research and Technological Applications (SRTA-CITY), Alexandria, EgyptInformation Technology College, Misr University for Science and Technology (MUST), 6th of October, Giza, Egypt; Computers and System Department, Faculty of Engineering, Al-Azhar University, Cairo, EgyptThe explosive growth of cloud usage encourages several challenges, especially high energy consumption of Cloud Data Centers (CDCs), new security risks to Virtual Machines (VMs) resulting from co-residency with other risky VMs on the same Physical Machine (PM), and the Quality of Service (QoS) degradation due to sharing resources. Many recent studies have proposed Dynamic VM Consolidation (DVMC) to save energy with minimum degradation of the QoS. However, due to the lack of reliable security measurements and consolidating VMs without any awareness of their security risk degrees, the overall security risk of the CDC may be increased. To tackle these challenges, this study presents a Security-aware DVMC (SDVMC) that consists of a Security Monitoring Module (SMM) and a SDVMC module. The SMM utilizes a three-dimensional security assessment model, while in the SDVMC module we propose a novel VM placement algorithm called Minimum Risk Increase (MRI) with Risk Increase Threshold (RITH). The proposed MRI with RITH VM placement algorithm selects the host that leads to minimum risk increase to the overall security risk while maintaining the risk increase for each VM does not exceed the value of the proposed RITH constraint; which is set according to the aims of the cloud provider. Simulation results show that using our approach with RITH 0.8 results in security improvement, overall risk was decreased by 2% to 5%, without negative impact on energy consumption or QoS. Moreover, using our approach with RITH less than 0.8 enables the tradeoff between energy consumption and the overall security risk. The maximum overall risk decrease ranged from 10% up to 40%, according to the intensive of the communication overhead between the VMs, while the used energy in its maximum was less than half if we used a non-power-ware VM allocation policy.http://www.sciencedirect.com/science/article/pii/S1110866520301572VM allocationDynamic VM consolidationSecurity aware VM consolidationSecurity aware VM placementCloud security |
collection |
DOAJ |
language |
English |
format |
Article |
sources |
DOAJ |
author |
Mohamed A. Elshabka Hanan A. Hassan Walaa M. Sheta Hany M. Harb |
spellingShingle |
Mohamed A. Elshabka Hanan A. Hassan Walaa M. Sheta Hany M. Harb Security-aware dynamic VM consolidation Egyptian Informatics Journal VM allocation Dynamic VM consolidation Security aware VM consolidation Security aware VM placement Cloud security |
author_facet |
Mohamed A. Elshabka Hanan A. Hassan Walaa M. Sheta Hany M. Harb |
author_sort |
Mohamed A. Elshabka |
title |
Security-aware dynamic VM consolidation |
title_short |
Security-aware dynamic VM consolidation |
title_full |
Security-aware dynamic VM consolidation |
title_fullStr |
Security-aware dynamic VM consolidation |
title_full_unstemmed |
Security-aware dynamic VM consolidation |
title_sort |
security-aware dynamic vm consolidation |
publisher |
Elsevier |
series |
Egyptian Informatics Journal |
issn |
1110-8665 |
publishDate |
2021-09-01 |
description |
The explosive growth of cloud usage encourages several challenges, especially high energy consumption of Cloud Data Centers (CDCs), new security risks to Virtual Machines (VMs) resulting from co-residency with other risky VMs on the same Physical Machine (PM), and the Quality of Service (QoS) degradation due to sharing resources. Many recent studies have proposed Dynamic VM Consolidation (DVMC) to save energy with minimum degradation of the QoS. However, due to the lack of reliable security measurements and consolidating VMs without any awareness of their security risk degrees, the overall security risk of the CDC may be increased. To tackle these challenges, this study presents a Security-aware DVMC (SDVMC) that consists of a Security Monitoring Module (SMM) and a SDVMC module. The SMM utilizes a three-dimensional security assessment model, while in the SDVMC module we propose a novel VM placement algorithm called Minimum Risk Increase (MRI) with Risk Increase Threshold (RITH). The proposed MRI with RITH VM placement algorithm selects the host that leads to minimum risk increase to the overall security risk while maintaining the risk increase for each VM does not exceed the value of the proposed RITH constraint; which is set according to the aims of the cloud provider. Simulation results show that using our approach with RITH 0.8 results in security improvement, overall risk was decreased by 2% to 5%, without negative impact on energy consumption or QoS. Moreover, using our approach with RITH less than 0.8 enables the tradeoff between energy consumption and the overall security risk. The maximum overall risk decrease ranged from 10% up to 40%, according to the intensive of the communication overhead between the VMs, while the used energy in its maximum was less than half if we used a non-power-ware VM allocation policy. |
topic |
VM allocation Dynamic VM consolidation Security aware VM consolidation Security aware VM placement Cloud security |
url |
http://www.sciencedirect.com/science/article/pii/S1110866520301572 |
work_keys_str_mv |
AT mohamedaelshabka securityawaredynamicvmconsolidation AT hananahassan securityawaredynamicvmconsolidation AT walaamsheta securityawaredynamicvmconsolidation AT hanymharb securityawaredynamicvmconsolidation |
_version_ |
1717376373827305472 |