【24h】

An advanced security-aware Cloud architecture

机译:一个先进的安全感知云体系结构

获取原文

摘要

Nowadays, Cloud offers many interesting features such as on-demand and pay-as-you-go resources, but induces new security problems in case a company wants to outsource its critical services. But since Clouds are shared between multiple tenants, both applications and execution environments need to be secured consistently in order to avoid possible attacks from malicious tenants. Moreover, if a large range of security mechanisms can improve the Cloud security, the configuration of those mechanisms to guarantee a global security property remains an open problem. Nowadays Clouds solutions lack two key features in order to realize it: an easy expression of security requirements and an actual enforcement of those requirements. This paper describes an overall architecture providing those features and an experiment run in order to demonstrate its validity. Our solution includes a language, a distribution engine and a security enforcement agent. The language eases the definition of the security properties required to plug an application into a Cloud. The distribution engine computes the sub-properties related to the different resources that must be deployed into the Cloud and coordinates the different enforcement agents associated to the provisioned resources. Our use-case addresses private hosting of customer data into the Cloud. The implementation and experiments show that the global security requirements (authentication and confidentiality) are satisfied when the application is scheduled within virtual machines and shared resources.
机译:如今,云提供了许多有趣的功能,例如按需和按需付费资源,但在公司希望外包其关键服务的情况下会引起新的安全问题。但由于云在多个租户之间共享,因此需要一致地保护应用程序和执行环境,以避免可能从恶意租户中攻击。此外,如果大量的安全机制可以提高云安全性,那么保证全球安全性的机制的配置仍然是一个公开问题。如今,云解决方案缺乏两个关键特征,以实现它:安全要求的简单表达和这些要求的实际执行。本文介绍了提供这些功能和实验运行的整体架构,以便展示其有效性。我们的解决方案包括语言,分发引擎和安全执行代理。该语言简化了将应用程序插入云所需的安全性属性的定义。分发引擎计算与必须部署到云中的不同资源相关的子属性,并协调与提供资源相关的不同强制代理。我们的用例地解决了客户数据的私人托管到云中。实施和实验表明,当应用程序在虚拟机和共享资源中计划时,满足全局安全要求(身份验证和机密性)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号