【24h】

Towards Cloud-Aware Vulnerability Assessments

机译:迈向云感知漏洞评估

获取原文

摘要

Vulnerability assessments are best practices for computer security and requirements for regulatory compliance. Potential and existing security holes can be identified during vulnerability assessments and security breaches could be averted. However, the unique nature of cloud computing environments requires more dynamic assessment techniques. The proliferation of cloud services and cloud-aware applications introduce more cloud vulnerabilities. But, current measures for identification, mitigation and prevention of cloud vulnerabilities do not suffice. Our investigations indicate a possible reason for this inefficiency to lapses in availability of precise, cloud vulnerability information. We observed also that most research efforts in the context of cloud vulnerability concentrate on IaaS, leaving other cloud models largely unattended. Similarly, most cloud assessment efforts tackle general cloud vulnerabilities rather than cloud specific vulnerabilities. Yet, mitigating cloud specific vulnerabilities is important for cloud security. Hence, this paper proposes a new approach that addresses the mentioned issues by monitoring, acquiring and adapting publicly available cloud vulnerability information for effective vulnerability assessments. We correlate vulnerability information from public vulnerability databases and develop Network Vulnerability Tests for specific cloud vulnerabilities. We have implemented, evaluated and verified the suitability of our approach.
机译:漏洞评估是计算机安全和法规遵从性要求的最佳实践。在漏洞评估期间,可以识别潜在的和现有的安全漏洞,并且可以避免安全漏洞。但是,云计算环境的独特性质需要更多的动态评估技术。云服务和云感知应用程序的激增引入了更多的云漏洞。但是,目前用于识别,缓解和预防云漏洞的措施还不够。我们的调查表明,这种效率低下可能导致无法准确提供云漏洞信息的可能原因。我们还观察到,在云漏洞方面,大多数研究工作都集中在IaaS上,而其他云模型在很大程度上无人值守。同样,大多数云评估工作都针对一般的云漏洞而不是特定于云的漏洞。但是,缓解特定于云的漏洞对于云安全非常重要。因此,本文提出了一种新方法,该方法通过监视,获取和调整公共可用的云漏洞信息来进行有效的漏洞评估,从而解决上述问题。我们将来自公共漏洞数据库的漏洞信息关联起来,并针对特定的云漏洞开发网络漏洞测试。我们已经实施,评估和验证了我们方法的适用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号