首页> 外文OA文献 >Securing the IaaS Service Model of Cloud Computing Against Compromised Components
【2h】

Securing the IaaS Service Model of Cloud Computing Against Compromised Components

机译:针对受损组件保护云计算的IaaS服务模型

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Cloud Computing is a new computing model, and its security aspects require special considerations. New characteristics of the cloud model have introduced new security challenges, and made some of the existing security techniques incompatible. Moreover, existing cloud environments are closed, operated by commercial providers, and their security mechanisms are proprietary as well as confidential. In other words, there is not much chance of observing how a real cloud environment is working, and how their providers adapt security measures to the new model.Therefore, we have chosen an open source cloud platform to build our own cloud environment. The OpenStack cloud software met our requirements, but it was not mature enough. We have done a deep analysis of this platform, identified potential attack targets in it, and discuss impacts of a successful attack.In order to secure our environment, the National Institute of Standards and Technology (NIST) incident handling guideline has been applied to the cloud model, and corresponding actions for each phase has been performed. To complete our study, we have proposed a set of cloud specific approaches that fulfill the incident handling requirements. These approaches address challenges identified in the guideline adaptation process. Additionally, we have studied the feasibility and compatibility of each approach against our deployed environment.Additionally, we also have submitted a paper to IEEE CloudCom 2011 conference, based on my thesis. A draft version of the paper is included in Appendix A.
机译:云计算是一种新的计算模型,其安全性方面需要特殊考虑。云模型的新特性带来了新的安全挑战,并使某些现有安全技术不兼容。此外,现有的云环境是封闭的,由商业提供商运营,并且它们的安全性机制既专有又保密。换句话说,观察真实云环境如何工作以及其提供商如何适应新模型的安全措施的机会很少。因此,我们选择了开源云平台来构建自己的云环境。 OpenStack云软件满足了我们的要求,但是还不够成熟。我们已经对该平台进行了深入分析,确定了其中的潜在攻击目标,并讨论了成功攻击的影响。为了保护我们的环境,美国国家标准技术研究院(NIST)事件处理指南已应用于云模型,并且每个阶段都已执行相应的操作。为了完成我们的研究,我们提出了一套满足事件处理要求的特定于云的方法。这些方法解决了指南适应过程中确定的挑战。此外,我们还研究了每种方法在部署环境中的可行性和兼容性。此外,基于我的论文,我们还向IEEE CloudCom 2011大会提交了论文。该文件的草案版本包含在附录A中。

著录项

  • 作者

    TaheriMonfared Aryan;

  • 作者单位
  • 年度 2011
  • 总页数
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号