首页> 外文期刊>Information Security Technical Report >Integrated assessment and mitigation of physical and digital security threats: Case studies on virtualization
【24h】

Integrated assessment and mitigation of physical and digital security threats: Case studies on virtualization

机译:物理和数字安全威胁的综合评估和缓解:虚拟化案例研究

获取原文
获取原文并翻译 | 示例
           

摘要

Virtualization is one of the enabling technologies of cloud computing. It turns once dedicated physical computing resources such as servers into digital resources that can be provisioned on demand. Cloud computing thus tends to replace physical with digital security controls, and cloud security must be understood in this context. In spite of extensive research on new hardware-enabled solutions such as trusted platforms, not enough is known about the actual physical-digital security trade-off in practice. In this paper, we review what is currently known about security aspects of the physical-digital trade-off, and then report on three case studies of private clouds that use virtualization technology, with the purpose of identifying generalizable guidelines for security trade-off analysis. We identify the important security properties of physical and digital resources, analyze how these have been traded off against each other in these cases, and what the resulting security properties were, and we identify limits to virtualization from a security point of view. The case studies show that physical security mechanisms all work through inertness and visibility of physical objects, whereas digital security mechanisms require monitoring and auditing. We conclude with a set of guidelines for trading off physical and digital security risks and mitigations. Finally, we show how our findings can be used to combine physical and digital security in new ways to improve virtualization and therefore also cloud security.
机译:虚拟化是云计算的促成技术之一。它将曾经的专用物理计算资源(例如服务器)转变为可以按需配置的数字资源。因此,云计算趋向于用数字安全控制代替物理,并且必须在这种情况下理解云安全。尽管对新的基于硬件的解决方案(例如受信任的平台)进行了广泛的研究,但实际上对实际的物理数字安全性的权衡尚不了解。在本文中,我们回顾了有关物理数字权衡的安全性方面的已知知识,然后报告了使用虚拟化技术的私有云的三个案例研究,目的是确定用于安全性权衡分析的通用准则。 。我们确定了物理和数字资源的重要安全属性,分析了在这些情况下如何相互权衡,以及所得到的安全属性是什么,并且从安全的角度确定了虚拟化的局限性。案例研究表明,物理安全机制都通过物理对象的惰性和可见性起作用,而数字安全机制则需要监视和审核。我们以一套权衡物理和数字安全风险和缓解措施的准则作为结束。最后,我们展示了如何将我们的发现用于新的方式将物理和数字安全性相结合,从而改善虚拟化以及云安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号