Auditing Security Compliance of the Virtualized Infrastructure in the Cloud: Application to OpenStack

被引:21
|
作者
Madi, Taous [1 ]
Majumdar, Suryadipta [1 ]
Wang, Yushun [1 ]
Jarraya, Yosr [2 ]
Pourzandi, Makan [2 ]
Wang, Lingyu [1 ]
机构
[1] Concordia Univ, CIISE, Montreal, PQ, Canada
[2] Ericsson Canada, Ericsson Secur Res, Montreal, PQ, Canada
关键词
Cloud; Virtualization; OpenStack; Security Auditing; Formal Verification; Co-residence; Isolation;
D O I
10.1145/2857705.2857721
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud service providers typically adopt the multi-tenancy model to optimize resources usage and achieve the promised cost-effectiveness. Sharing resources between different tenants and the underlying complex technology increase the necessity of transparency and accountability. In this regard, auditing security compliance of the provider's infrastructure against standards, regulations and customers' policies takes on an increasing importance in the cloud to boost the trust between the stakeholders. However, virtualization and scalability make compliance verification challenging. In this work, we propose an automated framework that allows auditing the cloud infrastructure from the structural point of view while focusing on virtualization-related security properties and consistency between multiple control layers. Furthermore, to show the feasibility of our approach, we integrate our auditing system into OpenStack, one of the most used cloud infrastructure management systems. To show the scalability and validity of our framework, we present our experimental results on assessing several properties related to auditing inter-layer consistency, virtual machines co-residence, and virtual resources isolation.
引用
收藏
页码:195 / 206
页数:12
相关论文
共 50 条
  • [1] Security Compliance Auditing of Identity and Access Management in the Cloud: Application to OpenStack
    Majumdar, Suryadipta
    Madi, Taous
    Wang, Yushun
    Jarraya, Yosr
    Pourzandi, Makan
    Wang, Lingyu
    Debbabi, Mourad
    2015 IEEE 7TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), 2015, : 58 - 65
  • [2] Cloud & Edge Trusted Virtualized Infrastructure Manager (VIM) - Security and Trust in OpenStack
    Sechkova, Teodora
    Barberis, Enrico
    Paolino, Michele
    2019 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE WORKSHOP (WCNCW), 2019,
  • [3] Data and infrastructure security auditing in cloud computing environments
    Rasheed, Hassan
    INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2014, 34 (03) : 364 - 368
  • [4] Auditing in Cloud Computing Solutions with OpenStack
    Konoor, Divya K.
    2016 IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING IN EMERGING MARKETS (CCEM), 2016, : 176 - 176
  • [5] FPGAs in the Cloud: Booting Virtualized Hardware Accelerators with OpenStack
    Byma, Stuart
    Steffan, J. Gregory
    Bannazadeh, Hadi
    Leon-Garcia, Alberto
    Chow, Paul
    2014 IEEE 22ND ANNUAL INTERNATIONAL SYMPOSIUM ON FIELD-PROGRAMMABLE CUSTOM COMPUTING MACHINES (FCCM 2014), 2014, : 109 - 116
  • [6] Virtualized Infrastructure Managers for edge computing: OpenVIM and OpenStack comparison
    Sechkova, Teodora
    Paolino, Michele
    Raho, Daniel
    2018 13TH IEEE INTERNATIONAL SYMPOSIUM ON BROADBAND MULTIMEDIA SYSTEMS AND BROADCASTING (BMSB), 2018,
  • [7] OpenStackDP: a scalable network security framework for SDN-based OpenStack cloud infrastructure
    Krishnan, Prabhakar
    Jain, Kurunandan
    Aldweesh, Amjad
    Prabu, P.
    Buyya, Rajkumar
    JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2023, 12 (01):
  • [8] OpenStackDP: a scalable network security framework for SDN-based OpenStack cloud infrastructure
    Prabhakar Krishnan
    Kurunandan Jain
    Amjad Aldweesh
    P. Prabu
    Rajkumar Buyya
    Journal of Cloud Computing, 12
  • [9] Managed infrastructure with IBM Cloud OpenStack Services
    Cash, S.
    Jain, V.
    Jiang, L.
    Karve, A.
    Kidambi, J.
    Lyons, M.
    Mathews, T.
    Mullen, S.
    Mulsow, M.
    Patel, N.
    IBM JOURNAL OF RESEARCH AND DEVELOPMENT, 2016, 60 (2-3)
  • [10] Security Vulnerability Assessment of OpenStack Cloud
    Ristov, Sasko
    Gusev, Marjan
    Donevski, Aleksandar
    2014 SIXTH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE, COMMUNICATION SYSTEMS AND NETWORKS (CICSYN), 2014, : 95 - 100