'Cloud Cartography' and Security update from August 2009

Can Internet attackers target a particular virtual machine on a large public cloud platform? A new paper outlines techniques third parties can use to map cloud infrastructure.

Data Center Knowledge

August 31, 2009

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Can Internet attackers target a particular virtual machine on a large public cloud platform? Craig Balding at Cloud Security points to a paper from researchers at MIT and Cal-San Diego titled "Hey, You, Get Off of My Cloud: Exploring Information Leakage in Third-Party Compute Clouds (PDF).” Here's a summary:

"Using the Amazon EC2 service as a case study, we show that it is possible to map the internal cloud infrastructure, identify where a particular target VM is likely to reside, and then instantiate new VMs until one is placed co-resident with the target. We explore how such placement can then be used to mount cross-VM side-channel attacks to extract information from a target VM on the same machine."

Craig says the paper is important in highlighting new avenues of attack for cloud security professionals to understand and defend. "There’s no EC2 '0-day', but that’s not the intent of the paper," Balding writes. "Rather, we are reminded that cloud platforms and technologies do bring some novel attacks that thus far have not really figured in much of the security conversation to date. We need more of this type of research to better understand what we are getting ourselves into."

Read more about:

Data Center Knowledge

About the Author

Data Center Knowledge

Data Center Knowledge, a sister site to ITPro Today, is a leading online source of daily news and analysis about the data center industry. Areas of coverage include power and cooling technology, processor and server architecture, networks, storage, the colocation industry, data center company stocks, cloud, the modern hyper-scale data center space, edge computing, infrastructure for machine learning, and virtual and augmented reality. Each month, hundreds of thousands of data center professionals (C-level, business, IT and facilities decision-makers) turn to DCK to help them develop data center strategies and/or design, build and manage world-class data centers. These buyers and decision-makers rely on DCK as a trusted source of breaking news and expertise on these specialized facilities.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like