【24h】

Cloud Security Automation Framework

机译:云安全自动化框架

获取原文

摘要

Cloud services have gained tremendous attention as a utility paradigm and have been deployed extensively across a wide range of fields. However, Cloud security is not catching up to the fast adoption of its services and remains one of the biggest challenges for Cloud Service Providers (CSPs) and Cloud Service Consumers (CSCs) from the industry, government, and academia. These institutions are increasingly faced with threats such as DoS/DDoS attacks, ransomware attacks, and data breaches that are affecting the confidentiality, integrity, and availability of the cloud system resources. In the current cloud systems, security requires manual translation of security requirements into controls. Such an approach can be for the most part labor intensive, tedious, and error-prone leading to inevitable misconfigurations rendering the system-at-hand vulnerable to misuse, either malicious or unintentional. Therefore, it is of utmost importance to automate the configuration of the cloud systems per the client's security requirements steering clear from the caveats of the manual approach. Furthermore, cloud systems need to be continuously monitored for any misconfigurations. This paper presents a methodology allowing for cloud security automation and demonstrates how a cloud environment can be automatically configured to implement a set of NIST SP 800-53 security controls. In addition, this paper shows how the implementation of these controls in the cloud systems can be continuously monitored and validated.
机译:Cloud Services作为实用范式的巨大关注,并已在广泛的领域广泛部署。然而,云安全不是宣布快速采用其服务,并且仍然是来自行业,政府和学术界的云服务提供商(CSP)和云服务消费者(CSC)的最大挑战之一。这些机构越来越受到DOS / DDOS攻击,赎金软件攻击以及影响云系统资源的机密性,完整性和可用性的数据漏所等威胁。在当前的云系统中,安全性需要将安全要求的手动转换为控制。这种方法可以是大多数劳动力密集,乏味的,易于出错的,导致不可避免的错误配置,使系统掌握易受滥用,无论是恶意还是无意。因此,从手动方法的警告可清楚地将客户的安全要求自动化云系统的配置是最重要的。此外,需要持续监测云系统以进行任何错误控制。本文呈现了一种允许云安全自动化的方法,并演示如何自动配置云环境以实现一组NIST SP 800-53安全控制。此外,本文可以持续监控和验证如何在云系统中实现这些控件的实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号