首页> 外文会议>IEEE International Conference on Communications >Making least privilege the low-hanging fruit in clouds
【24h】

Making least privilege the low-hanging fruit in clouds

机译:最小化云层中低垂的果实

获取原文

摘要

Failing to promote the least privilege principle in administration can lead to substantial vulnerabilities in cloud computing. A malicious insider like a compromised cloud administrator can affect security of data and workloads belonging to cloud customers. Enforcing the least privilege principle in cloud administration can fairly restrict the permissions of administrators and reduce the attack surface. However, writing a least privilege policy can be hard and error prone for cloud service providers. In this paper, we propose a framework called Least Privilege for Cloud (LPCloud) to address these concerns. LPCloud automatically produces policies for minimization of administrators' privileges at the granularity of representational state transfer (REST) application program interfaces (API), and enforces the policies without affecting current systems. Specifically, we introduce a novel algorithm to partition privileges based on dependencies between API calls. This paper presents design of LPCloud, including a service called Policy Generator which produces partitioned policies and a component named Policy Enforcer to enforce the policies. We implement a prototype of our framework in OpenStack Mitaka. Experiments indicate that LPCloud can produce proper policies to enforce the least privilege principle. Meantime, the average performance overhead is 10.1% which is in acceptable level.
机译:未能促进政府中最少的特权原则可以导致云计算中的大量漏洞。像受损的云管理员这样的恶意内幕innay可以影响属于Cloud客户的数据和工作负载的安全性。强制执行云管理中最少的权限原则可以公平地限制管理员的权限并减少攻击面。但是,编写最小的特权策略可能是艰难的并且容易出错的云服务提供商。在本文中,我们提出了一个框架,称为云(LPCloud)最不特权来解决这些问题。 LPCloud会自动为最小化代表状态传输(REST)应用程序接口(API)的粒度最小化管理员权限的策略,并在不影响当前系统的情况下执行策略。具体而言,我们将基于API呼叫之间的依赖性介绍一个新颖的算法来分区权限。本文介绍了LPCloud的设计,包括一个名为策略生成器的服务,它生成分区策略和一个名为Policy Enforcer的组件来强制执行策略。我们在OpenStack Mitaka实施了我们框架的原型。实验表明,LPCloud可以产生适当的政策,以强制执行最小的特权原则。同时,平均性能开销是10.1 \%,它是可接受的级别。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号