Cloud research isolates sensitive information
By Miya Knights,
Researchers from North Carolina State University and IBM are claiming a major breakthrough in the way cloud computing architectures protect sensitive information.
They have developed a new, experimental technique to isolate sensitive information and workload from the rest of the functions performed by a hypervisor – without, they claim, significantly affecting the system’s overall performance.
The new technique, called “Strongly Isolated Computing Environment” (SICE) introduces a different layer of security protection at the software framework level. It is designed to tackle longstanding concerns that attackers could take exploit hypervisor vulnerabilities to steal or corrupt confidential data in a cloud.
Dr. Peng Ning, a professor of computer science at North Carolina State and co-author of a paper describing the research, said the SICE technique significantly reduces the “surface” that can be attacked by malicious software.
“... Our approach relies on a software foundation called the Trusted Computing Base, or TCB, that has approximately 300 lines of code, meaning that only these 300 lines of code need to be trusted in order to ensure the isolation offered by our approach,” he said.
“Previous techniques have exposed thousands of lines of code to potential attacks. We have a smaller attack surface to protect.”
The technique is also designed to let programmers dedicate specific cores on commodity multi-core processors to the sensitive workload. By confining the sensitive workload to one or a few cores with strong isolation, and allowing other functions to operate separately, researchers said SICE provides both high assurance for the sensitive workload and efficient resource sharing in a cloud.
In testing, the researchers reported that the SICE framework generally took up approximately three per cent of the multi-core processors system’s performance overhead for workloads that do not require direct network access.
“That is a fairly modest price to pay for the enhanced security,” Ning said. However, he added that more research was needed to further speed up the workloads that require interactions with the network.
For further coverage of cloud computing visit our sister site Cloud Pro.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Cloud Analysis & Insight
Windows Azure VM Beta for AWS users (and cloud virgins)
Steve’s been playing with the Windows Azure beta. But what does he think? Read on to find out.
- Citrix takes on the mobile cloud at Synergy
- Getting ready for EMC World
- Montreux Jazz Festival: Storage in a different light
- IBM Impact 2012: Scott Hebner, IBM
- Google, and that 5GB free storage
- Q&A: Carter George executive director of Dell storage
- Enterprises must find secure Dropbox for employees
- IBM Pulse 2012: Q&A, Angel Diaz, software standards vice president
- Top 10 tips to get the most out of Dropbox
Latest Cloud Reviews
CA ARCserve Backup r16
Rating: ![]()
- Egnyte HybridCloud review
- Dell PowerEdge C6100 review
- Iomega StorCenter px6-300d review
- Head to Head: Google Apps vs Microsoft Office 365
- QNap TS-559 Pro II TurboNAS review
- ThinPrint Printer Dashboard review: First Look
- Samsung Chromebook Series 5 review
- Iomega StorCenter px4-300r review
- Websense Triton Security Gateway Anywhere review
advertisement
Most popular
- UK regulator shuts down Angry Birds scam
- Apple iPad 3 vs iPad 2 head-to-head review
- IBM bans use of Siri on iPhones
- Chromebooks: What's gone wrong?
- HP plans massive job cuts
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell EqualLogic PS6100XS review
- Macs and Android under malware threat
- RIM loses its head of sales
- Local fibre broadband needs common standards
Latest News Videos in Cloud
IT PRO Podcast: CES 2011
In the first podcast of 2011, we talk with Adam Griffin of Dell and Barry Collins of PCPro about tablets, the cloud and all the other exciting...
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.




