首页> 外文会议>IEEE International Conference on Computer and Communications >Attack tree analysis of Man in the Cloud attacks on client device synchronization in cloud computing
【24h】

Attack tree analysis of Man in the Cloud attacks on client device synchronization in cloud computing

机译:云计算中的人在云计算中对客户端设备同步攻击的攻击树分析

获取原文

摘要

Cloud computing has many irrefutable advantages and one of the most attractive benefits thereof that is seeing users migrate to the cloud is the ability to synchronize each of their devices with the cloud. A user can be in a different locality with a different device altogether but with the advent of cloud synchronization, he is able to access and replicate data changes to all of his synchronized devices. However, this convenience comes at a cost. The framework that is implemented to actualize this adorable functionality leaves much to be desired in that authorization to synchronize with the cloud only requires a synchronization token offered to the user upon his one-time authentication. This entails that whoever presents this synchronization token is able to synchronize with the user's data both locally and on the cloud without the need to provide any login credentials. The task of the attacker therefore is to acquire this synchronization token which is always stored locally on the cloud user's device and this task is actualized via a Man in the Cloud (MITC) attack. This paper employs attack trees to analyze the constituents of a MITC attack process in the synchronization of client devices in cloud computing. We further propose from the analysis, areas of concentration when deploying preventative measures.
机译:云计算具有许多不可否认的优势,而其最吸引人的优势之一就是可以看到用户迁移到云,这是使他们的每个设备与云同步的能力。用户可以通过不同的设备位于不同的位置,但是随着云同步的到来,他能够访问并将数据更改复制到其所有同步设备。但是,这种便利性是有代价的。为实现这一可爱功能而实现的框架还有很多需要改进的地方,因为与云同步的授权只需要在用户一次身份验证时提供给用户的同步令牌即可。这就要求提供此同步令牌的人都可以在本地和云上与用户数据同步,而无需提供任何登录凭据。因此,攻击者的任务是获取始终存储在云用户设备上的此同步令牌,并且此任务是通过“云中的人”(MITC)攻击来实现的。本文利用攻击树来分析云计算中客户端设备同步中的MITC攻击过程的组成。我们从分析中进一步提出部署预防措施时的重点领域。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号