Abstract
Cloud computing has become crucial for the commercial world due to its computational capacity, storage capabilities, scalability, software integration, and billing convenience. Initially, clouds were relatively homogeneous, but now diverse machine configurations in heterogeneous clouds are recognized for their improved application performance and energy efficiency. This shift is driven by the integration of various hardware to accommodate diverse user applications. However, alongside these advancements, security threats like micro-architectural attacks are increasing concerns for cloud providers and users. Studies like Repttack and Cloak & Co-locate highlight the vulnerability of heterogeneous clouds to co-location attacks, where attacker and victim instances are placed together. The ease of these attacks isn’t solely linked to heterogeneity but also correlates with how heterogeneous the target systems are. Despite this, no numerical metrics exist to quantify cloud heterogeneity. This article introduces the Heterogeneity Score (HeteroScore) to evaluate server setups and instances. HeteroScore significantly correlates with co-location attack security. The article also proposes strategies to balance diversity and security. This study pioneers the quantitative analysis connecting cloud heterogeneity and infrastructure security.
Author supplied keywords
Cite
CITATION STYLE
Fang, C., Nazari, N., Omidi, B., Wang, H., Puri, A., Arora, M., … Khasawneh, K. (2025). Assessing and Mitigating Heterogeneity-Driven Security Threats in the Cloud. ACM Transactions on Internet Technology, 25(4). https://doi.org/10.1145/3746228
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.