首页> 外文OA文献 >Automated security compliance tool for the cloud
【2h】

Automated security compliance tool for the cloud

机译:自动化的云安全合规工具

摘要

Security, especially security compliance, is a major concern that is slowing down the large scale adoption of cloud computing in the enterprise environment. Business requirements, governmental regulations and trust are among the reasons why the enterprises require certain levels of security compliance from cloud providers.So far, this security compliance or auditing information has been generated by security specialists manually. This process involves manual data collection and assessment which is slow and incurs a high cost. Thus, there is a need for an automated compliance tool to verify and express the compliance level of various cloud providers. Such a tool can reduce the human intervention and eventually reduce the cost and time by verifying the compliance automatically. Also, the tool will enable the cloud providers to share their security compliance information using a common framework. In turn, the common framework allows clients to compare various cloud providers based on their security needs.Having these goals in mind, we have developed architecture to build an automated security compliance tool for a cloud computing platform. We have also outlined four possible approaches to achieve this automation. These possible four approaches refer to four design patterns to collect data from the cloud system and these are: API, vulnerability scanning, log analysis and manual entry.Finally, we have implemented a proof-of-concept prototype of this automated security compliance tool using the proposed architecture. This prototype implementation is integrated with OpenStack cloud platform, and the results are exposed to the users of the cloud following the CloudAudit API structure defined by Cloud Security Alliance.
机译:安全(尤其是安全合规性)是一个主要问题,它正在减缓企业环境中云计算的大规模采用。业务要求,政府法规和信任度是企业要求云提供商提供一定级别的安全合规性的原因。到目前为止,这种安全合规性或审核信息是由安全专家手动生成的。此过程涉及手动数据收集和评估,这很慢并且会导致高成本。因此,需要一种自动合规工具来验证和表达各种云提供商的合规水平。这样的工具可以减少人工干预,并通过自动验证合规性来最终减少成本和时间。此外,该工具还将使云提供商可以使用通用框架共享其安全合规性信息。反过来,通用框架允许客户根据他们的安全需求比较各种云提供商。考虑到这些目标,我们开发了用于为云计算平台构建自动化安全合规工具的体系结构。我们还概述了实现此自动化的四种可能方法。这四种可能的方法涉及从云系统收集数据的四种设计模式,分别是:API,漏洞扫描,日志分析和手动输入。最后,我们使用以下方法实现了该自动化安全合规工具的概念验证原型。拟议的架构。该原型实现与OpenStack云平台集成在一起,并且按照Cloud Security Alliance定义的CloudAudit API结构将结果暴露给云用户。

著录项

  • 作者

    Ullah Kazi Wali;

  • 作者单位
  • 年度 2012
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号