
Cloud computing is a new computing model which uses virtualization technology, distributed computing, parallel computing and other existing technologies to achieve cloud service virtualization and economies of scale, whilst increasingly overwhelming cloud security issues has brought great challenges and concerns to the cloud services providers and cloud users, especially trust and privacy issues with regard to cloud computing and cloud shared storage associated security issues. In the paper, we expound the basic concepts of cloud computing, deployment models, service models and key features, analyze and outline the currently highlighted cloud security issues, report the status quo of cloud computing security, investigate the prevalent and typical cloud computing security problem key solving techniques, and thus render a comprehensive cloud computing security technical reference model, which is composed of associated cloud security solving techniques that result from inevitably multi-faceted cloud security issues. The model is expected to alleviate prominent cloud security issues. This paper generalizes cloud security technology research directions and further development space of cloud security technology and standardization.
Cloud computing is moving from being a testing ground for isolated projects to being a strategic approach of the entire business organization. So the choice among the possible cloud offers, with a strong focus on the choice of services that enable better processes and projects of the business lines, is gaining importance. Nevertheless the heterogeneity of the Cloud services, resources, technology and service levels offered by the several providers make difficult to decide. Besides the inconveniences caused by the "lock-in", give rise to the need for developers to be able to develop an application regardless of where it is released, structuring and building it in a vendor agnostic way so that it is possible to deploy on the provider that best fits them at the moment. The mOSAIC project aims at designing and developing an innovative open-source API and platform that enables applications to be Cloud providers' neutral and to negotiate Cloud services as requested by their users, allowing automatic discovery, matchmaking, and thus supporting selection, brokering, interoperability end even composition of Cloud Services among multiple Clouds. In this paper, we illustrate the interoperation of the two components, the Semantic Engine and the Cloud Agency for the agnostic retrieval, discovery and brokering of cloud services. The focus will be put on the way to support the Cloud Application Developer to express the requirements and services/resources in vendor agnostic way and to translate automatically these requirements into a neutral format in order to compare it with the different offers of providers and to broker the best one according to defined policies.
A notion of increasing the energy efficiency of HPC machines or applications has reached the global HPC community forum in recent years. This has opened up several interesting possibilities that reduces the energy consumption of applications, including an energy consumption analysis mechanism which delves into the reason behind the energy consumption bottlenecks of applications. In order to easily analyze the energy consumption of applications (from machine to machine), a need for a dedicated energy consumption analysis tool has undoubtedly enthused application developers or users. In general, when applications were analyzed for performance bottlenecks in modern HPC architectures, such as, exascale machines which have more than tens of thousands of cores, a performance analysis tool might deliver a huge performance dataset. Querying such data in a short span of time can efficiently be done using document based NoSQL database systems. This paper proposes an online-based energy consumption analysis mechanism of HPC applications using EnergyAnalyzer Performance Database (EAPerfDB), a NoSQL-based performance database feature, of EnergyAnalyzer tool. The EnergyAnalyzer tool uses semantic agents in a distributed fashion to undergo the energy consumption analysis of HPC applications. In addition, the paper explores the findings of the energy consumption analysis of High Performance Computing Challenge (HPCC) benchmarks when NoSQL-based EnergyAnalyzer tool was used at the HPCCLoud Research Laboratory of our premise.
Security measures, such as proving data integrity, became more important with the increase in popularity of cloud data storage services. Dynamic Provable Data Possession (DPDP) was proposed in the literature to enable the cloud server to prove to the client that her data is kept intact, even in a dynamic setting where the client may update her files. Realizing that variable-sized updates are very inefficient in DPDP (in the worst case leading to uploading the whole file again), Flexible DPDP (FlexDPDP) was proposed.In this paper, we analyze FlexDPDP scheme and propose optimized algorithms. We show that the initial pre-processing phase at the client and server sides during the file upload (generally the most time-consuming operation) can be efficiently performed by parallelization techniques that result in a speed up of 6 with 8 cores. We propose a way of handling multiple updates at once both at the server and the client side, achieving an efficiency gain of 60% at the server side and 90% in terms of the client's update verification time.We deployed the optimized FlexDPDP on the large-scale network testbed PlanetLab and demonstrate the efficiency of our proposed optimizations on multi-client scenarios according to real workloads based on version control system traces.
The increased use of virtualized environments has led to numerous research efforts about the possibilities and restrictions of the use of these virtualized environments in cloud computing or for resource consolidation. However, most of these studies are limited to a level of performance analysis, that does not address the effects of concurrency among the various virtual environments, and how to mitigate these effects. The study presented below proposes the concept of affinity, based on the correct combination of certain applications classes, that are able to share the same environment, at the same time, causing less loss of performance. The results show that there are combinations of applications that could share the same environment with minimum loss, but there are combinations that must be avoided. This study also shows the influence of the type of parallel library used for the implementation of these applications.
Cloud computing strives to achieve the long-standing vision of making computing a utility, similar to electricity, telephone, and water services. This article discusses several research challenges that need to be addressed in order to realize the full potential of cloud computing and get computing closer to being a utility.
The interactions enabled by the popular sites of the Web 2.0 are largely confined to the virtual world of the Internet, thus failing to engage people in relevant interactions with people, contents or resources in their physical environment. In this paper, we motivate the potential of automatically establishing sporadic social networks among people (acquaintances or strangers) who happen to be physically close to one another at a certain moment. We present the design of one platform intended to provide solutions from the lowest level of establishing ad-hoc connections among nearby mobile devices, up to the highest level of automatically identifying the most relevant pieces of information to deliver at any time. A number of application scenarios are presented, along with technical details of a solution to empower ad-hoc communications by means of a virtualization layer.
The cloud computing concept has significantly influenced how information is delivered and managed in large scale distributed systems today. Cloud computing is currently expected to reduce the economic cost of using computational and data resources, and is therefore particularly appealing to small and medium scale companies (who may not wish to maintain in-house IT departments). To provide economies of scale, providers of Cloud computing infrastructure make significant use of virtualisation techniques – in which processes of various tenants sharing the same physical resources are separated logically using a hypervisor. In spite of its wide adoption in Cloud computing systems, virtualisation technology suffers from many security and privacy issues. We outline security challenges that remain in the use of virtualisation techniques to support multiple customers on the same shared infrastructure. We also illustrate, using an experiment, how data leakage occurs when multiple VMs are executed on the same physical infrastructure, leading to unauthorised access to (previously) deleted data.
Most of the current cloud computing platforms offer Infrastructure as a Service (IaaS) model, which aims to provision basic virtualized computing resources as on-demand and dynamic services. Nevertheless, a single cloud provider may not have limitless resources to offer to its users, hence the notion of an Inter-Cloud environment where a cloud can use the infrastructure resources of other clouds. However, there is no common framework in existence that allows the service owners to seamlessly provision even some basic services across multiple cloud service providers, albeit not due to any inherent incompatibility or proprietary nature of the foundation technologies on which these cloud platforms are built. In this paper we present a novel solution which aims to cover a gap in a subsection of this problem domain. Our solution offers a security architecture that enables service owners to provision a dynamic and service-oriented secure virtual private network on top of multiple cloud IaaS providers. It does this by leveraging the scalability, robustness and flexibility of peer-to-peer overlay techniques to eliminate the manual configuration, key management and peer churn problems encountered in setting up the secure communication channels dynamically, between different components of a typical service that is deployed on multiple clouds. We present the implementation details of our solution as well as experimental results detailing the overheads of our solution carried out on two commercial clouds.
In Cloud computing, Infrastructure-as-a-Service (IaaS) can be purchased with three pricing schemes, namely reserved pricing, on-demand pricing and spot pricing. Within the spot pricing model, the spot Cloud resources usually refer to the spare compute capacity that can be auctioned in a spot market. A commercial spot market has been established since Amazon launched its spot instance service. Unlike the straightforward fixed-price schemes, the market-driven mechanism behind spot pricing is inevitably sophisticated for both Cloud consumers and providers. In addition, the de facto vendor Amazon does not disclose any backend detail except for its recent spot price history. To help practitioners better understand the spot market and help researchers identify research opportunities, we focused on Amazon’s spot service and investigated the relevant studies of the Cloud spot market. The result of our investigation has been organized and summarized into an overview of the current research, as described in this chapter.