Department of Computer Science
Self-service Cloud Computing
- Publication Type: Conference Publications
- Publication Date: 2012-10-01
- Journal Volume: ACM CCS'12
- Abstract:
Modern cloud computing infrastructures use virtual machine monitors (VMMs) that often include a large and complex administrative domain with privileges to inspect client VM state. Attacks against or misuse of the administrative domain can compromise client security and privacy. Moreover, these VMMs provide clients inflexible control over their own VMs, as a result of which clients have to rely on the cloud provider to deploy useful services, such as VM introspection-based security tools.
We introduce a new self-service cloud (SSC) computing model that addresses these two shortcomings. SSC splits administrative privileges between a system-wide domain and per-client administrative domains. Each client can manage and perform privileged system tasks on its own VMs, thereby providing flexibility. The system-wide administrative domain cannot inspect the code, data or computation of client VMs, thereby ensuring security and privacy. SSC also allows providers and clients to establish mutually trusted services that can check regulatory compliance while respecting client privacy. We have implemented SSC by modifying the Xen hypervisor. We demonstrate its utility by building user domains to perform privileged tasks such as memory introspection, storage intrusion detection, and anomaly detection.
Upcoming Events
| 05 May 2026; - 11:00AM - 12:00PM Advances in Watermarking Large Language Models |
| 05 May 2026; - 11:20AM - 12:20PM Trustworthy AI for Structured Reasoning: Conformal Guarantees in Knowledge Graph Question Answering |
| 06 May 2026; - 03:30PM - 04:30PM Towards Universal and Interactive Medical Image Segmentation |







