【24h】

An effective auditing scheme for cloud computing

机译:一种有效的云计算审计方案

获取原文

摘要

In this paper, we present a novel secure auditing scheme for cloud computing systems. Several auditing schemes have been proposed for the cloud, which periodically trigger the auditing function. These schemes are designed to monitor the performance and behavior of the cloud. One major problem with these kind of schemes is that they are vulnerable to the transient attack (also known as the timed scrubbing attack). Our secure auditing scheme is able to prevent the transient attack via modification of the Linux auditing daemon - auditd, which creates attestable logs. Our scheme utilizes the System Management Mode (SMM) for integrity checks and the Trusted Platform Module (TPM) chip for attestable security. Specifically, we modify the auditing daemon protocol such that it records a hash of each audit log entry to the TPM's Platform Configuration Register (PCR), which gives us an attestable history of every command executed on the cloud server. We perform real experiments on two cloud servers and the results show that the overhead of our scheme is very small.
机译:在本文中,我们提出了一种针对云计算系统的新型安全审核方案。已针对云提出了几种审核方案,这些方案会定期触发审核功能。这些方案旨在监视云的性能和行为。这些方案的主要问题是它们容易受到瞬时攻击(也称为定时清理攻击)。我们的安全审计方案能够通过修改Linux审计后台程序-auditd来防止瞬态攻击,该后台程序创建了可证明的日志。我们的方案使用系统管理模式(SMM)进行完整性检查,并使用可信平台模块(TPM)芯片以确保安全性。具体来说,我们修改了审核守护程序协议,使其将每个审核日志条目的哈希记录到TPM的平台配置寄存器(PCR),从而为我们提供了在云服务器上执行的每个命令的可证明历史。我们在两个云服务器上进行了真实的实验,结果表明我们的方案的开销很小。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号