Security-aware dynamic VM consolidation

The explosive growth of cloud usage encourages several challenges, especially high energy consumption of Cloud Data Centers (CDCs), new security risks to Virtual Machines (VMs) resulting from co-residency with other risky VMs on the same Physical Machine (PM), and the Quality of Service (QoS) degrad...

Full description

Bibliographic Details
Main Authors: Mohamed A. Elshabka, Hanan A. Hassan, Walaa M. Sheta, Hany M. Harb
Format: Article
Language:English
Published: Elsevier 2021-09-01
Series:Egyptian Informatics Journal
Subjects:
Online Access:http://www.sciencedirect.com/science/article/pii/S1110866520301572
id doaj-3e89206fe02d47419fb13ef8c0002bfd
record_format Article
spelling doaj-3e89206fe02d47419fb13ef8c0002bfd2021-09-19T04:55:11ZengElsevierEgyptian Informatics Journal1110-86652021-09-01223277284Security-aware dynamic VM consolidationMohamed A. Elshabka0Hanan A. Hassan1Walaa M. Sheta2Hany M. Harb3Informatics Research Institute, City of Scientific Research and Technological Applications (SRTA-CITY), Alexandria, Egypt; Corresponding author at: Informatics Research Institute, City of Scientific Research and Technological Applications (SRTA-CITY), Alexandria, Egypt.Informatics Research Institute, City of Scientific Research and Technological Applications (SRTA-CITY), Alexandria, EgyptInformatics Research Institute, City of Scientific Research and Technological Applications (SRTA-CITY), Alexandria, EgyptInformation Technology College, Misr University for Science and Technology (MUST), 6th of October, Giza, Egypt; Computers and System Department, Faculty of Engineering, Al-Azhar University, Cairo, EgyptThe explosive growth of cloud usage encourages several challenges, especially high energy consumption of Cloud Data Centers (CDCs), new security risks to Virtual Machines (VMs) resulting from co-residency with other risky VMs on the same Physical Machine (PM), and the Quality of Service (QoS) degradation due to sharing resources. Many recent studies have proposed Dynamic VM Consolidation (DVMC) to save energy with minimum degradation of the QoS. However, due to the lack of reliable security measurements and consolidating VMs without any awareness of their security risk degrees, the overall security risk of the CDC may be increased. To tackle these challenges, this study presents a Security-aware DVMC (SDVMC) that consists of a Security Monitoring Module (SMM) and a SDVMC module. The SMM utilizes a three-dimensional security assessment model, while in the SDVMC module we propose a novel VM placement algorithm called Minimum Risk Increase (MRI) with Risk Increase Threshold (RITH). The proposed MRI with RITH VM placement algorithm selects the host that leads to minimum risk increase to the overall security risk while maintaining the risk increase for each VM does not exceed the value of the proposed RITH constraint; which is set according to the aims of the cloud provider. Simulation results show that using our approach with RITH 0.8 results in security improvement, overall risk was decreased by 2% to 5%, without negative impact on energy consumption or QoS. Moreover, using our approach with RITH less than 0.8 enables the tradeoff between energy consumption and the overall security risk. The maximum overall risk decrease ranged from 10% up to 40%, according to the intensive of the communication overhead between the VMs, while the used energy in its maximum was less than half if we used a non-power-ware VM allocation policy.http://www.sciencedirect.com/science/article/pii/S1110866520301572VM allocationDynamic VM consolidationSecurity aware VM consolidationSecurity aware VM placementCloud security
collection DOAJ
language English
format Article
sources DOAJ
author Mohamed A. Elshabka
Hanan A. Hassan
Walaa M. Sheta
Hany M. Harb
spellingShingle Mohamed A. Elshabka
Hanan A. Hassan
Walaa M. Sheta
Hany M. Harb
Security-aware dynamic VM consolidation
Egyptian Informatics Journal
VM allocation
Dynamic VM consolidation
Security aware VM consolidation
Security aware VM placement
Cloud security
author_facet Mohamed A. Elshabka
Hanan A. Hassan
Walaa M. Sheta
Hany M. Harb
author_sort Mohamed A. Elshabka
title Security-aware dynamic VM consolidation
title_short Security-aware dynamic VM consolidation
title_full Security-aware dynamic VM consolidation
title_fullStr Security-aware dynamic VM consolidation
title_full_unstemmed Security-aware dynamic VM consolidation
title_sort security-aware dynamic vm consolidation
publisher Elsevier
series Egyptian Informatics Journal
issn 1110-8665
publishDate 2021-09-01
description The explosive growth of cloud usage encourages several challenges, especially high energy consumption of Cloud Data Centers (CDCs), new security risks to Virtual Machines (VMs) resulting from co-residency with other risky VMs on the same Physical Machine (PM), and the Quality of Service (QoS) degradation due to sharing resources. Many recent studies have proposed Dynamic VM Consolidation (DVMC) to save energy with minimum degradation of the QoS. However, due to the lack of reliable security measurements and consolidating VMs without any awareness of their security risk degrees, the overall security risk of the CDC may be increased. To tackle these challenges, this study presents a Security-aware DVMC (SDVMC) that consists of a Security Monitoring Module (SMM) and a SDVMC module. The SMM utilizes a three-dimensional security assessment model, while in the SDVMC module we propose a novel VM placement algorithm called Minimum Risk Increase (MRI) with Risk Increase Threshold (RITH). The proposed MRI with RITH VM placement algorithm selects the host that leads to minimum risk increase to the overall security risk while maintaining the risk increase for each VM does not exceed the value of the proposed RITH constraint; which is set according to the aims of the cloud provider. Simulation results show that using our approach with RITH 0.8 results in security improvement, overall risk was decreased by 2% to 5%, without negative impact on energy consumption or QoS. Moreover, using our approach with RITH less than 0.8 enables the tradeoff between energy consumption and the overall security risk. The maximum overall risk decrease ranged from 10% up to 40%, according to the intensive of the communication overhead between the VMs, while the used energy in its maximum was less than half if we used a non-power-ware VM allocation policy.
topic VM allocation
Dynamic VM consolidation
Security aware VM consolidation
Security aware VM placement
Cloud security
url http://www.sciencedirect.com/science/article/pii/S1110866520301572
work_keys_str_mv AT mohamedaelshabka securityawaredynamicvmconsolidation
AT hananahassan securityawaredynamicvmconsolidation
AT walaamsheta securityawaredynamicvmconsolidation
AT hanymharb securityawaredynamicvmconsolidation
_version_ 1717376373827305472