提出一种面向多租户的关键虚拟机动态迁移方法。首先,根据租户对虚拟机的安全需求设定关键虚拟机的比例,减少虚拟机动态迁移的数量;然后,通过虚拟机之间共存时间约束条件最大化降低虚拟机动态迁移的频率;最后,以最小化迁移开销作为虚拟机迁移的目标函数,进一步降低虚拟机迁移带来的开销。实验表明,与现有的防御方法相比,该方法在有效防御侧信道攻击的前提下,能够减少对网络服务性能的影响,降低虚拟机迁移的成本,更加适用于大规模的网络场景。
A dynamic migration method of critical virtual machines for multi-tenancy was proposed. Firstly, the te- nants can set ratio of critical virtual machines according to tenant's security requirements, then the dynamic migra- tion frequency of virtual machines were maximized by the coexistence time constraints between virtual machines, finally the migration cost was minimized as an object function for the virtual machines migrated to further reduce the migration cost. Simulation experiments demonstrate that the proposed approach can reduce the impact on the performance of network services and the cost of virtual machines migration, and is more suitable for large-scale network scenarios under the premise of effective defense side-channel attacks.