【24h】

Security Risk Assessment of Cloud Carrier

机译:云载波的安全风险评估

获取原文

摘要

Cloud computing based delivery model has been adopted by end-users and enterprises to reduce enterprise IT costs and complexities. The ability to offload user software and data to cloud datacenters has raised many security and privacy concerns over the cloud computing model. Significant research efforts have focused on hypervisor security and low-layer operating system implementations in cloud datacenters. Unfortunately, the role of a cloud carrier on the security and privacy of user software and data has not been well studied. A cloud carrier represents the wide area network that provides the connectivity and transport of cloud services between cloud consumers and cloud providers. In this paper, we present a risk assessment framework to study the security risk of the cloud carrier between cloud users and two cloud providers. The risk assessment framework leverages the National Vulnerability Database (NVD) to examine the security vulnerabilities of operating systems of routers within the cloud carrier. This framework provides the quantifiable security metrics of each cloud carrier, which enables cloud users to select quality of security services among cloud providers. Such security metric information is very useful in the Service Level Agreement (SLA) negotiation between a cloud user and a cloud provider. It can be also used to build a tool for verifying the commitment of an SLA. Furthermore, we implement this framework on Amazon Web Services and Windows Azure, respectively. Our experiments show that the security risks of cloud carriers on these two commercial clouds are significantly different. This finding provides guidance for a network provider to improve the security of cloud carriers.
机译:基于云计算的交付模式已被最终用户和企业采用,以降低企业的成本和复杂性。将用户软件和数据卸载到云数据中心的能力提高了云计算模型的许多安全性和隐私问题。显着的研究工作侧重于云数据中心中的虚拟机管理程序安全性和低层操作系统实现。不幸的是,云承运人对用户软件和数据的安全和隐私的作用并未得到很好的研究。云载波代表广域网,提供云消费者和云提供商之间的云服务的连接和传输。在本文中,我们提出了一个风险评估框架,以研究云用户和两个云提供商之间的云载波的安全风险。风险评估框架利用国家漏洞数据库(NVD)来检查云载波中的路由器操作系统的安全漏洞。此框架提供每个云载波的可量化的安全指标,使云用户能够在云提供商之间选择安全服务的质量。这种安全度量信息在云用户和云提供商之间的服务级别协议(SLA)协商中非常有用。它也可以用于构建一个工具,用于验证SLA的承诺。此外,我们分别在Amazon Web服务和Windows Azure上实施此框架。我们的实验表明,这两个商业云上的云载体的安全风险显着不同。这一发现为网络提供商提高了云运营商的安全性提供了指导。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号