首页> 外文会议>International Conference on Information and Communications Security >Simau: A Dynamic Privilege Management Mechanism for Host in Cloud Datacenters
【24h】

Simau: A Dynamic Privilege Management Mechanism for Host in Cloud Datacenters

机译:SIMAU:云数据中心主机的动态特权管理机制

获取原文

摘要

Nowadays, a majority of cyber-attacks are associated with the insider threats owing to improper privileges management. Though a number of access control mechanisms have been carried out, the insider threats are continuously increasing. In cloud, however, the physical machines of datacenters are still exposed to danger. Without the trusted hosts as the foundation, any further measurements for virtual machines are in vain. In this paper, we introduce Simau: a mechanism that constrains the privileges of root on each host in the cloud. It deploys a decision engine in user-space to support the variable security policies. The scope of Simau covers both kernel-space and user-space. Under Simau, once a system administrator logs into a host, he has only the least privileges to finish his missions and all his requests for privileged operations are determined by Simau. The experiments at last show good performance of our mechanism.
机译:如今,由于特权管理不当,大多数网络攻击都与内部威胁有关。虽然已经进行了许多访问控制机制,但内部威胁是不断增加的。然而,在云中,数据中心的物理机器仍然暴露于危险。如果没有受信任的主机作为基础,则虚拟机的任何进一步测量都是徒劳的。在本文中,我们介绍了Simau:一个限制云中每个主机的根root权限的机制。它部署了用户空间中的决策引擎,以支持可变安全策略。 Simau的范围涵盖内核空间和用户空间。在Simau下,一旦系统管理员登录到一个主机,他只有最少的特权来完成他的任务,并由Simau确定他的所有特权运营请求。最后的实验表现出我们机制的良好表现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号