Skip to main content

CQSTR: Securing cross-tenant applications with Cloud containers

Publication ,  Conference
Zhai, Y; Yin, L; Chase, J; Ristenpart, T; Swift, M
Published in: Proceedings of the 7th ACM Symposium on Cloud Computing Socc 2016
October 5, 2016

Cloud providers are in a position to greatly improve the trust clients have in network services: IaaS platforms can isolate services so they cannot leak data, and can help verify that they are securely deployed. We describe a new system called CQSTR that allows clients to verify a service's security properties. CQSTR provides a new cloud container abstraction similar to Linux containers but for VM clusters within IaaS clouds. Cloud containers enforce constraints on what software can run, and control where and how much data can be communicated across service boundaries. With CQSTR, IaaS providers can make assertions about the security properties of a service running in the cloud. We investigate implementations of CQSTR on both Amazon AWS and OpenStack. With AWS, we build on virtual private clouds to limit network access and on authorization mechanisms to limit storage access. However, with AWS certain security properties can be checked only by monitoring audit logs for violations after the fact. We modified OpenStack to implement the full CQSTR model with only modest code changes. We show how to use CQSTR to build more secure deployments of the data analytics frameworks PredictionIO, PacketPig, and SpamAssassin. In experiments on CloudLab we found that the performance impact of CQSTR on applications is near zero.

Duke Scholars

Published In

Proceedings of the 7th ACM Symposium on Cloud Computing Socc 2016

DOI

Publication Date

October 5, 2016

Start / End Page

223 / 236
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Zhai, Y., Yin, L., Chase, J., Ristenpart, T., & Swift, M. (2016). CQSTR: Securing cross-tenant applications with Cloud containers. In Proceedings of the 7th ACM Symposium on Cloud Computing Socc 2016 (pp. 223–236). https://doi.org/10.1145/2987550.2987558
Zhai, Y., L. Yin, J. Chase, T. Ristenpart, and M. Swift. “CQSTR: Securing cross-tenant applications with Cloud containers.” In Proceedings of the 7th ACM Symposium on Cloud Computing Socc 2016, 223–36, 2016. https://doi.org/10.1145/2987550.2987558.
Zhai Y, Yin L, Chase J, Ristenpart T, Swift M. CQSTR: Securing cross-tenant applications with Cloud containers. In: Proceedings of the 7th ACM Symposium on Cloud Computing Socc 2016. 2016. p. 223–36.
Zhai, Y., et al. “CQSTR: Securing cross-tenant applications with Cloud containers.” Proceedings of the 7th ACM Symposium on Cloud Computing Socc 2016, 2016, pp. 223–36. Scopus, doi:10.1145/2987550.2987558.
Zhai Y, Yin L, Chase J, Ristenpart T, Swift M. CQSTR: Securing cross-tenant applications with Cloud containers. Proceedings of the 7th ACM Symposium on Cloud Computing Socc 2016. 2016. p. 223–236.

Published In

Proceedings of the 7th ACM Symposium on Cloud Computing Socc 2016

DOI

Publication Date

October 5, 2016

Start / End Page

223 / 236