JOURNAL ARTICLE

Security-Aware Resource Allocation in Clouds

Abstract

Elasticity and economic considerations make Infrastructure-as-a-Service (IaaS) clouds attractive propositions for hosting enterprise IT applications. However, for prospective cloud customers, that potential is tempered by concerns, chief among them being security. We consider the problem of resource allocation in IaaS clouds while factoring in reachability and access control requirements of the cloud virtual machines (VMs). We describe a security-aware resource allocation framework that allows for effective enforcement of defense-in-depth for cloud VMs by determining (1) the grouping of VMs into security groups based on the similarity of their reachability requirements, and (2) the placement of virtual machines in a manner that reduces residual risks for individual VMs as well as security groups. We formalize security-aware resource allocation as a Constraint Satisfaction Problem (CSP), which can be solved using widely available Satisfiability Modulo Theories (SMT) solvers. Our experimental evaluation shows the effectiveness of our approach in reducing risk and improving manageability of security configurations for the cloud VMs.

Keywords:
Computer science Cloud computing Reachability Virtual machine Cloud computing security Resource allocation Distributed computing Access control Computer security Computer network Theoretical computer science Operating system

Metrics

25
Cited By
6.54
FWCI (Field Weighted Citation Impact)
16
Refs
0.96
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Cloud Computing and Resource Management
Physical Sciences →  Computer Science →  Information Systems
Cloud Data Security Solutions
Physical Sciences →  Computer Science →  Information Systems
Distributed systems and fault tolerance
Physical Sciences →  Computer Science →  Computer Networks and Communications

Related Documents

BOOK-CHAPTER

Location-Aware Multi-user Resource Allocation in Distributed Clouds

Jiaxin LiDongsheng LiJing ZhengYong Quan

Communications in computer and information science Year: 2014 Pages: 152-162
JOURNAL ARTICLE

Topology-Aware Resource Allocation for IoT Services in Clouds

Xin LiZhen LianXiaolin QinJie Wu

Journal:   IEEE Access Year: 2018 Vol: 6 Pages: 77880-77889
JOURNAL ARTICLE

QoS-Aware Resource Allocation for Video Transcoding in Clouds

Lei WeiJianfei CaiChuan Heng FohBingsheng He

Journal:   IEEE Transactions on Circuits and Systems for Video Technology Year: 2016 Vol: 27 (1)Pages: 49-61
© 2026 ScienceGate Book Chapters — All rights reserved.