首页> 外文会议>IEEE International Conference on Cloud Computing Technology and Science >Security Compliance Auditing of Identity and Access Management in the Cloud: Application to OpenStack
【24h】

Security Compliance Auditing of Identity and Access Management in the Cloud: Application to OpenStack

机译:云中身份和访问管理的安全合规性审核:在OpenStack中的应用

获取原文

摘要

Cloud computing has seen a lot of interests and adoption lately. Nonetheless, the widespread adoption of cloud is still being hindered by the lack of transparency and accountability, which has traditionally been ensured through security compliance auditing techniques. Auditing in cloud, however, presents many new challenges in data collection and processing (e.g., data format inconsistency and lack of correlation due to the heterogeneity of cloud infrastructures) and in verification (e.g., prohibitive performance overhead due to the sheer scale of cloud infrastructures and their self-provisioning, elastic, and dynamic nature). In this paper, we propose a security compliance auditing framework for cloud, with special focus on identity and access management, and we implement and evaluate the framework based on OpenStack, one of the most popular cloud management systems. Our experimental results show that auditing with formal methods in large cloud environment is realistic (e.g., our auditing solution can handle 60 thousand users in less than one minute).
机译:最近,云计算引起了人们的广泛兴趣和采用。但是,由于缺乏透明性和问责制,仍然阻碍了云的广泛采用,而这通常是通过安全合规性审核技术来确保的。但是,在云中进行审核在数据收集和处理(例如,由于云基础架构的异构性导致数据格式不一致和缺乏相关性)和验证(例如,由于云基础架构规模庞大而导致的性能开销过大)方面面临许多新挑战以及它们的自我配置,弹性和动态特性)。在本文中,我们提出了一个针对云的安全合规性审核框架,特别侧重于身份和访问管理,并且我们基于最流行的云管理系统之一的OpenStack来实现和评估该框架。我们的实验结果表明,在大型云环境中使用形式化方法进行审核是现实的(例如,我们的审核解决方案可以在不到一分钟的时间内处理6万名用户)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号