首页> 外文会议>IEEE 35th Annual IEEE International Conference on Computer Communications >Understanding security group usage in a public IaaS cloud
【24h】

Understanding security group usage in a public IaaS cloud

机译:了解公共IaaS云中的安全组用法

获取原文
获取原文并翻译 | 示例

摘要

To ensure security, cloud service providers employ security groups as a key tool for cloud tenants to protect their virtual machines (VMs) from attacks. However, security groups can be complex and often hard to configure, which may result in security vulnerabilities that impact the entire cloud platform. The goal of this paper is to investigate and understand how cloud tenants configure security groups and to assist them in designing better security groups. We first conduct a measurement-based analysis of security group configuration and usage by tenants in an IaaS cloud. We then propose and develop a tool called Socrates, which enables tenants to visualize and hence understand the static and dynamic access relations among VMs. Socrates also helps diagnose potential misconfigurations and provides suggestions to refine security group configurations based on observed traffic traversing tenants' VMs. Applying Socrates to all tenants hosted on the IaaS cloud, we analyze the common usage (“good” as well as “bad” practices) of cloud security groups and report the key lessons learned in our study. To the best of our knowledge, our work is the first to analyze cloud security group usage based on real-world datasets, and to develop a system to help cloud tenants understand, diagnose and better refine their security group configurations.
机译:为了确保安全,云服务提供商将安全组用作云租户的关键工具,以保护其虚拟机(VM)免受攻击。但是,安全组可能很复杂,并且通常难以配置,这可能会导致影响整个云平台的安全漏洞。本文的目的是调查和了解云租户如何配置安全组,并协助他们设计更好的安全组。我们首先对IaaS云中的租户进行基于度量的安全组配置和使用情况分析。然后,我们提出并开发了一个名为Socrates的工具,该工具使租户可以可视化并因此了解VM之间的静态和动态访问关系。 Socrates还可帮助诊断潜在的错误配置,并根据观察到的流向租户VM的流量提供建议,以优化安全组配置。将Socrates应用于IaaS云上托管的所有租户,我们分析了云安全组的常见用法(“好”和“坏”做法),并报告了我们在研究中获得的主要经验教训。据我们所知,我们的工作是第一个基于实际数据集分析云安全组使用情况,并开发出一个系统来帮助云租户了解,诊断和更好地改进其安全组配置。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号