Auditing Security Compliance of the Virtualized Infrastructure in the Cloud: Application to OpenStack

被引:21
|
作者
Madi, Taous [1 ]
Majumdar, Suryadipta [1 ]
Wang, Yushun [1 ]
Jarraya, Yosr [2 ]
Pourzandi, Makan [2 ]
Wang, Lingyu [1 ]
机构
[1] Concordia Univ, CIISE, Montreal, PQ, Canada
[2] Ericsson Canada, Ericsson Secur Res, Montreal, PQ, Canada
关键词
Cloud; Virtualization; OpenStack; Security Auditing; Formal Verification; Co-residence; Isolation;
D O I
10.1145/2857705.2857721
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud service providers typically adopt the multi-tenancy model to optimize resources usage and achieve the promised cost-effectiveness. Sharing resources between different tenants and the underlying complex technology increase the necessity of transparency and accountability. In this regard, auditing security compliance of the provider's infrastructure against standards, regulations and customers' policies takes on an increasing importance in the cloud to boost the trust between the stakeholders. However, virtualization and scalability make compliance verification challenging. In this work, we propose an automated framework that allows auditing the cloud infrastructure from the structural point of view while focusing on virtualization-related security properties and consistency between multiple control layers. Furthermore, to show the feasibility of our approach, we integrate our auditing system into OpenStack, one of the most used cloud infrastructure management systems. To show the scalability and validity of our framework, we present our experimental results on assessing several properties related to auditing inter-layer consistency, virtual machines co-residence, and virtual resources isolation.
引用
收藏
页码:195 / 206
页数:12
相关论文
共 50 条
  • [21] Harnessing Cloud Technologies for a Virtualized Distributed Computing Infrastructure
    di Costanzo, Alexandre
    de Assuncao, Marcos Dias
    Buyya, Rajkumar
    IEEE INTERNET COMPUTING, 2009, 13 (05) : 24 - 33
  • [22] Virtualized Security Function Placement for Security Service Chaining in Cloud
    Wu, Hongjing
    Zhang, Yan
    Yang, Huiran
    Yu, Guangxi
    Cao, Jiuyue
    2018 IEEE 24TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS (ICPADS 2018), 2018, : 628 - 637
  • [23] Mutual Auditing Framework for Service Level Security Auditing in Cloud
    Sasmal, Soumitra
    Pan, Indrajit
    2017 THIRD IEEE INTERNATIONAL CONFERENCE ON RESEARCH IN COMPUTATIONAL INTELLIGENCE AND COMMUNICATION NETWORKS (ICRCICN), 2017, : 297 - 302
  • [24] A forensics and compliance auditing framework for critical infrastructure protection
    Henriques, Joao
    Caldeira, Filipe
    Cruz, Tiago
    Simoes, Paulo
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2023, 42
  • [25] Feasibility of automated information security compliance auditing
    Longley, D.
    Branagan, M.
    Caelli, W. J.
    Kwok, L. F.
    PROCEEDINGS OF THE IFIP TC 11/ 23RD INTERNATIONAL INFORMATION SECURITY CONFERENCE, 2008, : 493 - +
  • [26] A Survey on Forensics and Compliance Auditing for Critical Infrastructure Protection
    Henriques, Joao
    Caldeira, Filipe
    Cruz, Tiago
    Simoes, Paulo
    IEEE ACCESS, 2024, 12 : 2409 - 2444
  • [27] Tutorial: Building Secure and Scalable Private Cloud Infrastructure with OpenStack
    Babar, Ali
    Ramsey, Ben
    PROCEEDINGS OF THE 2015 IEEE 19TH INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE WORKSHOPS AND DEMONSTRATIONS (EDOCW 2015), 2015, : 166 - 166
  • [28] aDock: A Cloud Infrastructure Experimentation Environment based on OpenStack and Docker
    Affetti, L.
    Bresciani, G.
    Guinea, S.
    2015 IEEE 8TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING, 2015, : 203 - 210
  • [29] Security Problems in Cloud Infrastructure
    Djenna, Amir
    Batouche, Mohamed
    2014 INTERNATIONAL SYMPOSIUM ON NETWORKS, COMPUTERS AND COMMUNICATIONS, 2014,
  • [30] Development of a Virtualized Application Networking Infrastructure Node
    Redmond, Keith
    Bannazadeh, Hadi
    Chow, Paul
    Leon-Garcia, Alberto
    2009 IEEE GLOBECOM WORKSHOPS, 2009, : 351 - 356