首页> 外文会议>International Conference on Engineering of Complex Computer Systems >Improving Tenants' Trust in SaaS Applications Using Dynamic Security Monitors
【24h】

Improving Tenants' Trust in SaaS Applications Using Dynamic Security Monitors

机译:使用动态安全监视器提高租户对SaaS应用程序的信任

获取原文

摘要

It is almost impossible to prove that a given software system achieves an absolute security level. This becomes more complicated when addressing multi-tenant cloud-based SaaS applications. Developing practical security properties and metrics to monitor, verify, and assess the behavior of such software systems is a feasible alternative to such problem. However, existing efforts focus either on verifying security properties or security metrics but not both. Moreover, they are either hard to adopt, in terms of usability, or require design-time preparation to support monitoring of such security metrics and properties which is not feasible for SaaS applications. In this paper, we introduce, to the best of our knowledge, the first unified monitoring platform that enables SaaS application tenants to specify, at run-time, security metrics and properties without design-time preparation and hence increases tenants' trust of their cloud-assets security. The platform automatically converts security metrics and properties specifications into security probes and integrates them with the target SaaS application at run-time. Probes-generated measurements are fed into an analysis component that verifies the specified properties and calculates security metrics' values using aggregation functions. This is then reported to SaaS tenants and cloud platform security engineers. We evaluated our platform expressiveness and usability, soundness, and performance overhead.
机译:几乎不可能证明给定的软件系统达到了绝对的安全级别。当处理基于多租户云的SaaS应用程序时,这变得更加复杂。开发实用的安全属性和度量以监视,验证和评估此类软件系统的行为是解决此类问题的可行替代方案。但是,现有的工作要么集中在验证安全性属性上,要么集中在验证安全性指标上,而不是同时验证两者。此外,就可用性而言,它们要么难以采用,要么需要进行设计时准备以支持对此类安全性指标和属性的监视,而这对于SaaS应用程序是不可行的。在本文中,我们就我们所知,介绍了第一个统一的监控平台,该平台使SaaS应用程序租户可以在运行时指定安全指标和属性,而无需进行设计时准备,从而提高了租户对其云的信任度-资产安全。该平台会自动将安全性指标和属性规范转换为安全性探针,并在运行时将其与目标SaaS应用程序集成。探针生成的度量将被馈送到分析组件,该组件将验证指定的属性并使用聚合函数来计算安全度量的值。然后将其报告给SaaS租户和云平台安全工程师。我们评估了平台的表现力,可用性,健全性和性能开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号