论文部分内容阅读
针对当前IaaS环境下虚拟机中软件版本不易管理以及软件更新不及时带来的安全问题,研究了一种适用于云计算环境下租户虚拟机应用软件更新和系统补丁升级的服务机制。首先,该机制建立了统一的管理框架,实现了软件和补丁的便捷管理;其次,该机制借助Linux网络命名空间的方式将更新服务接入到不同租户的虚拟网络,实现了不同租户的更新服务的灵活接入和安全隔离;最后,针对更新相同软件和补丁的批量虚拟机,采用可靠多播的方式进行软件和补丁分发,大大减小了网络流量,节省了网络资源。实验结果表明,该机制可以有效地提高软件和补丁的分发效率、节省网络资源、减小CPU的消耗,同时保证不同租户更新服务的隔离性。
Aiming at the problem that the software version in the virtual machine is not easy to manage and the software update is not timely in the current IaaS environment, a service mechanism suitable for updating the application software and updating the system patch of the virtual machine in the cloud computing environment is studied. First of all, the mechanism establishes a unified management framework and implements the convenient management of software and patches. Secondly, the mechanism accesses the update network to the virtual network of different tenants by means of the Linux network namespace, and implements the update service of different tenants Flexible access and secure isolation. Finally, the software and patch distribution are implemented in a reliable multicast mode for batches of virtual machines that update the same software and patches, which greatly reduces network traffic and saves network resources. Experimental results show that this mechanism can effectively improve the software and patch distribution efficiency, save network resources and reduce CPU consumption, while ensuring the isolation of different tenant update services.