Researchers discover new way to patch holes in the 'cloud'

November 29, 2010 By Matt Shipman

Researchers from North Carolina State University and IBM have invented a way to update computer systems packaged in virtual machines in a computer “cloud” – even when those programs are offline.

The new cloud computing patch tool developed by NC State and IBM is called Nuwa and protects (VMs) from cyber-attacks by ensuring that they always receive important upgrades. In addition, the researchers have determined that offline application of security patches is more than four times faster than online patch application. The tool is named after a Chinese goddess who patched a hole in the sky.

A paper describing the research, “Always Up-to-date – Scalable Offline Patching of VM Images in a Compute Cloud,” will be presented Dec. 10 at the Annual Computer Security Applications Conference in Austin, Texas.

“We’ve designed a way to patch these virtual machines while they are offline, so that they are kept up to date in terms of security protection,” says Dr. Peng Ning, professor of computer science at NC State and co-author of a paper describing the research. “Current patching systems are designed for computers that are online and they don’t work for dormant computers or virtual machines. The tool we developed automatically analyzes the ‘script’ that dictates how a security patch is installed, and then automatically re-writes the script to make it compatible with an offline system.”

Nuwa leverages a collection of techniques developed by IBM, called Mirage, that is used for performing efficient offline introspection and manipulation of a large collection of VM images, to allow cloud administrators to patch multiple VMs simultaneously. A program already exists that allows cloud computing systems to operate more efficiently by saving one version of a computer file that is used by multiple VMs – rather than saving the same file repeatedly for each individual VM. Nuwa takes advantage of this technology and, by patching one file, can ultimately protect all of the VMs that use that file.

NC State and IBM have successfully tested and evaluated Nuwa on the IBM Research Compute Cloud, a compute cloud that is used by IBM researchers worldwide.

Cloud computing enables users to create many VMs on one large computing platform, with each VM being able to perform various computer functions. It is so easy to create these VMs, that businesses and individuals will often create them to perform very specific tasks on a periodic basis. Because many of these VMs are used infrequently, they are often left dormant for extended periods of time, so that they are not consuming energy and computer resources when not in use.

These dormant periods pose a significant security problem, because VMs that are offline do not receive security upgrades, known as patches. This leaves the VMs vulnerable to cyber-attacks when they are brought back online. The VMs are particularly vulnerable if they have been left dormant for months, and missed significant patches.

More information: “Always Up-to-date – Scalable Offline Patching of VM Images in a Compute Cloud” by Wu Zhou, et al. IBM T. J. Watson Research Center. Presented: Dec. 10, 2010, at the Annual Computer Security Applications Conference, Austin, Texas.

Provided by North Carolina State University search and more info website

Filter


Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

cisono
Dec 10, 2010

Rank: not rated yet
But if they are offline, surely they cannot be attacked? I must be missing something...
Rank not rated yet
Relevant PhysicsForums posts
  • Ideas to mitigate risk of 911 calls being misdirected
    created23 hours ago
  • Live scribe pen?
    createdMay 10, 2012
  • Shallow water flow simulation
    createdMay 07, 2012
  • Tablet for taking notes?
    createdMay 05, 2012
  • Best fit tablet for me?
    createdMay 05, 2012
  • Measure of Informaton
    createdMay 04, 2012
  • More from Physics Forums - Computing & Technology

More news stories

Yahoo kills 'Livestand' just 6 months after debut

(AP) -- Yahoo is killing a tablet magazine called Livestand just six months its debut on the iPad.

Technology / Business

created 2 hours ago | popularity not rated yet | comments 0

Yahoo! ditches digital newsstand for iPads

Yahoo! shuttered its fledgling digital newsstand for iPads on Friday in what it said was the start of a product purge intended to make the floundering Internet pioneer more nimble.

Technology / Internet

created 3 hours ago | popularity not rated yet | comments 0

Facebook IPO debacle raises investor dander

The spate of complaints and investigations over the Facebook stock offering suggests big institutions had an edge over small investors, raising questions about the process.

Technology / Business

created 4 hours ago | popularity not rated yet | comments 0

Shareholders vote to take China's Alibaba unit private

Minority shareholders of Alibaba.com on Friday voted in favour of a proposal by its parent Alibaba Group Holding to take the Hong Kong-listed online trading unit private, the company said.

Technology / Business

created 4 hours ago | popularity not rated yet | comments 0

Computers excel at identifying smiles of frustration (w/ Video)

(Phys.org) -- Researchers at the Massachusetts Institute of Technology (MIT) in the US have trained computers to recognize smiles, and they have turned out to be more adept at recognizing smiles of frustration ...

Technology / Computer Sciences

created 15 hours ago | popularity 4 / 5 (2) | comments 1 | with audio podcast report


It's in the genes: Research pinpoints how plants know when to flower

Scientists believe they've pinpointed the last crucial piece of the 80-year-old puzzle of how plants "know" when to flower.

High-speed method to aid search for solar energy storage catalysts

Eons ago, nature solved the problem of converting solar energy to fuels by inventing the process of photosynthesis.

Researchers solve structure of human protein critical for silencing genes

In a study published in the journal Cell on May 24, Cold Spring Harbor Laboratory (CSHL) scientists describe the three-dimensional atomic structure of a human protein bound to a piece of RNA that "guides" the pr ...

Dragon makes history with space station docking

The private company SpaceX made history Friday with the docking of its Dragon capsule to the International Space Station, the most impressive feat yet in turning routine spaceflight over to the commercial ...

Tongue analysis software uses ancient Chinese medicine to warn of disease

For 5,000 years, the Chinese have used a system of medicine based on the flow and balance of positive and negative energies in the body. In this system, the appearance of the tongue is one of the measures used to classify ...

Of mice and mental models: Neuroscientific implications of risk-optimized behavior in the mouse

(Medical Xpress) -- Regardless of an organism’s biological complexity, every encephalized animal continuously makes under-informed behavioral choices that can have serious consequences. Despite its ubiquity, ...