Cloud fingerprinting: using clock skews to determine co-location of virtual machines

Download
Author
Wasek, Christopher J.
Date
2016-09Advisor
Xie, Geoffrey G.
Kolsch, Mathias
Metadata
Show full item recordAbstract
Cloud computing has quickly revolutionized computing practices of organizations, to include the Department of Defense. However, security concerns over co-location attacks have arisen from the consolidation inherent in virtualization and from physical hardware hosting virtual machines for multiple businesses and organizations. Current cloud security methods, such as Amazon's Virtual Private Cloud, have evolved defenses against most of the well-known fingerprinting and mapping methods in order to prevent malicious users from determining virtual machine co-location on the same hardware. Our solution to co-locating virtual machines unhindered was to derive their clock skews, or the temporal deviation of the system clock over time. Capturing normal TCP traffic to analyze timestamps from a virtual machine in the cloud, our results were inconclusive in demonstrating that co-located virtual machines will have similar clock skews due to large, inconsistent packet delays. Our research demonstrates a potential vulnerability in cloud defenses so that cloud users and providers can take appropriate steps to prevent malicious co-location attacks.
Rights
This publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States.Related items
Showing items related by title, author, creator and subject.
-
Free field spatialized aural cues for synthetic environments
Roesli, John T. (Monterey, California. Naval Postgraduate School, 1994-09);Commercially available spatial audio systems for synthetic environments suffer from excessive cost ~md the requirement for in-house application software development. The purpose of this work wru; to develop a low cost audio ... -
Helicopter Urban Navigation Training using virtual environments
Wright, George T. (Monterey, California. Naval Postgraduate School, 2000-06-01);Helicopter missions are never defined as "...successful navigation to and return from a location." Navigation, in and of itself, is not the mission - it is, however, a skill that all helicopter pilots are expected to master ... -
Hyper-NPSNET: a virtual world with an integrated 3D hypertext
Daley, John Alexander (Monterey, California. Naval Postgraduate School, 1992-03);This thesis proposes an extension to the NPSNET 3D virtual world prototype to provide an integrated 3D hypertext. This hypertext would be embedded into the virtual world, and would provide the capability for real-time or ...