Protecting Secrets in Cloud Applications using Moving-Target Defense

dc.contributor.authorVAN BENNEKUM, ERIK
dc.contributor.authorSCHULZE, FELIX
dc.contributor.departmentChalmers tekniska högskola / Institutionen för data och informationstekniksv
dc.contributor.departmentChalmers University of Technology / Department of Computer Science and Engineeringen
dc.contributor.examinerPathan, Risat
dc.contributor.supervisorHassan, Ahmed
dc.date.accessioned2024-01-12T09:26:48Z
dc.date.available2024-01-12T09:26:48Z
dc.date.issued2023
dc.date.submitted2023
dc.description.abstractOver the last decade, more and more IT systems are moved from on-premise or co-located servers to cloud infrastructure to take advantage of the reduced cost, complexity and time-to-market that cloud infrastructure brings. However, a shared environment, such as a server shared between different customers, exposes customers to sophisticated side-channel attacks, where a malicious virtual machine can steal information from any of the other virtual machines running on the same host. Thisthesis proposes a solution to this problem by utilizing moving-target defense, where the virtual machine of the customer is moved to different physical machines on a regular basis to avoid any adversary from having enough time to perform long-running side-channel attacks. To solve the connectivity problem, where clients need to connect to this moving virtual machine, a reverse proxy is used that keeps track of the current location of the virtual machine and keeps the connections alive. Benchmarks show that the added latency is insignificant for most applications, and the slight reduction in throughput is unlikely to become a bottleneck.
dc.identifier.coursecodeDATX05
dc.identifier.urihttp://hdl.handle.net/20.500.12380/307517
dc.language.isoeng
dc.setspec.uppsokTechnology
dc.subjectmoving-target defense
dc.subjectmtd
dc.subjectsecurity
dc.subjectcybersecurity
dc.subjectcloud
dc.subjectproxy
dc.subjectvirtual machine
dc.subjectvm
dc.subjectside-channel attack
dc.titleProtecting Secrets in Cloud Applications using Moving-Target Defense
dc.type.degreeExamensarbete för masterexamensv
dc.type.degreeMaster's Thesisen
dc.type.uppsokH
local.programmeComputer systems and networks (MPCSN), MSc

Ladda ner

Original bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
CSE 23-121 EB FS.pdf
Storlek:
2.09 MB
Format:
Adobe Portable Document Format

License bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
license.txt
Storlek:
2.35 KB
Format:
Item-specific license agreed upon to submission
Beskrivning: