首页> 外文会议>IEEE World Congress on Services >Embedding a Distributed Auditing Mechanism in the Service Cloud
【24h】

Embedding a Distributed Auditing Mechanism in the Service Cloud

机译:在服务云中嵌入分布式审核机制

获取原文
获取外文期刊封面目录资料

摘要

The Cloud Security Alliance identified the "notorious nine" threats for cloud computing. The range of these threats across the cloud indicates that centralized prevention and detection would be highly inefficient, potentially reporting incidents to tenants well after they occur and are difficult to mitigate. This paper presents an auditing framework for the service cloud that distributes logging, monitoring, and reporting at the local service level, at the application or session level that can involve multiple tenant services, and at the cloud level where corroboration and verification of threats takes place. To verify the forensic coverage of the framework, a set of CAPEC attack patterns are investigated to match attack evidence gathering and mitigation techniques with the proposed distributed detection and mitigation levels of the framework.
机译:云安全联盟确定了云计算的“臭名昭著的九个”威胁。跨云计算的这些威胁的范围表明,集中的预防和检测将非常低效,可能在事件发生后很长时间将事件报告给租户,并且难以缓解。本文提出了一种服务云的审核框架,该框架在本地服务级别,可能涉及多个租户服务的应用程序或会话级别以及发生威胁的确证和验证的云级别上分发日志记录,监视和报告。 。为了验证框架的法证覆盖范围,研究了一组CAPEC攻击模式,以将攻击证据收集和缓解技术与框架的分布式检测和缓解级别相匹配。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号