首页> 外文会议>International Conference on Engineering of Complex Computer Systems >Improving Tenants' Trust in SaaS Applications Using Dynamic Security Monitors
【24h】

Improving Tenants' Trust in SaaS Applications Using Dynamic Security Monitors

机译:使用动态安全监视器提高租户信任的萨斯应用

获取原文

摘要

It is almost impossible to prove that a given software system achieves an absolute security level. This becomes more complicated when addressing multi-tenant cloud-based SaaS applications. Developing practical security properties and metrics to monitor, verify, and assess the behavior of such software systems is a feasible alternative to such problem. However, existing efforts focus either on verifying security properties or security metrics but not both. Moreover, they are either hard to adopt, in terms of usability, or require design-time preparation to support monitoring of such security metrics and properties which is not feasible for SaaS applications. In this paper, we introduce, to the best of our knowledge, the first unified monitoring platform that enables SaaS application tenants to specify, at run-time, security metrics and properties without design-time preparation and hence increases tenants' trust of their cloud-assets security. The platform automatically converts security metrics and properties specifications into security probes and integrates them with the target SaaS application at run-time. Probes-generated measurements are fed into an analysis component that verifies the specified properties and calculates security metrics' values using aggregation functions. This is then reported to SaaS tenants and cloud platform security engineers. We evaluated our platform expressiveness and usability, soundness, and performance overhead.
机译:几乎不可能证明给定的软件系统实现了绝对的安全级别。当解决基于多租户云的SaaS应用时,这变得更加复杂。开发要监视,验证和评估此类软件系统的行为的实用安全性质和指标是对此类问题的可行替代品。但是,现有的努力将重点关注验证安全性属性或安全度量,但不是两者。此外,在可用性方面难以采用,或者需要设计时准备,以支持监控这种安全度量和属性,这对于SaaS应用不可行。在本文中,我们介绍了我们的知识,这是第一个统一的监控平台,使SaaS应用租户能够在运行时,安全指标和属性在没有设计时准备的情况下,并因此增加了租户的云信任-assets安全。该平台会自动将安全度量和属性规范转换为安全探针,并在运行时将它们与目标SaaS应用程序集成。探测生成的测量被馈送到分析组件中,验证指定属性,并使用聚合函数计算安全度量值。然后将这报告给SaaS租户和云平台安全工程师。我们评估了我们的平台表现力和可用性,合理性和性能开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号