Security-Aware Resource Allocation Framework for Cloud Computing Environments
Abstract
Most cloud schedulers determine workload placement primarily by assessing whether candidate hosts have sufficient CPU, memory, and bandwidth. Security factors, such as patch status, vulnerability exposure, co-resident threats, and historical host behavior, are rarely integrated directly into resource allocation decisions. When considered, security is often applied as a simple pass or fail filter alongside conventional capacity-based scheduling. This paper proposes the Security-Aware Resource Allocation Framework (SARAF), which incorporates security indicators directly into workload placement decisions. For each candidate host, SARAF calculates a composite Security Score based on three components: recency-weighted trust history, vulnerability exposure, and short-window dynamic threat signals. This score is combined with resource availability through a weighted Allocation Score that automatically adjusts according to the security sensitivity of the incoming workload. Placement is performed using a greedy algorithm with bounded lookahead to reduce the concentration of workloads on highly ranked hosts. SARAF was evaluated using CloudSim with 50 heterogeneous hosts and 300 virtual machine requests across three workload regimes and compared with FCFS, Round Robin, Traditional Load Balancing, and Trust-Based Allocation. Under moderate workload conditions, SARAF reduced high-risk placements by approximately 61% compared with Round Robin and 38% compared with Trust-Based Allocation, while maintaining resource utilization within a few percentage points of the best throughput-focused baseline. These security improvements involve measurable tradeoffs, including approximately fivefold higher placement latency than FCFS and increased rejection rates under bursty workloads. Overall, the results demonstrate that security-aware scheduling can substantially reduce risky workload placements while preserving competitive resource utilization.