Auditing Security Compliance of the Virtualized Infrastructure in the Cloud: Application to OpenStack

被引:21
|
作者
Madi, Taous [1 ]
Majumdar, Suryadipta [1 ]
Wang, Yushun [1 ]
Jarraya, Yosr [2 ]
Pourzandi, Makan [2 ]
Wang, Lingyu [1 ]
机构
[1] Concordia Univ, CIISE, Montreal, PQ, Canada
[2] Ericsson Canada, Ericsson Secur Res, Montreal, PQ, Canada
关键词
Cloud; Virtualization; OpenStack; Security Auditing; Formal Verification; Co-residence; Isolation;
D O I
10.1145/2857705.2857721
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud service providers typically adopt the multi-tenancy model to optimize resources usage and achieve the promised cost-effectiveness. Sharing resources between different tenants and the underlying complex technology increase the necessity of transparency and accountability. In this regard, auditing security compliance of the provider's infrastructure against standards, regulations and customers' policies takes on an increasing importance in the cloud to boost the trust between the stakeholders. However, virtualization and scalability make compliance verification challenging. In this work, we propose an automated framework that allows auditing the cloud infrastructure from the structural point of view while focusing on virtualization-related security properties and consistency between multiple control layers. Furthermore, to show the feasibility of our approach, we integrate our auditing system into OpenStack, one of the most used cloud infrastructure management systems. To show the scalability and validity of our framework, we present our experimental results on assessing several properties related to auditing inter-layer consistency, virtual machines co-residence, and virtual resources isolation.
引用
收藏
页码:195 / 206
页数:12
相关论文
共 50 条
  • [31] DLoc: Distributed Auditing for Data Location Compliance in Cloud
    Eskandari, Mojtaba
    Crispo, Bruno
    de Oliveira, Anderson Santana
    DATA PRIVACY MANAGEMENT, CRYPTOCURRENCIES AND BLOCKCHAIN TECHNOLOGY, 2017, 10436 : 202 - 218
  • [32] Cloud Security Auditing: Challenges and Emerging Approaches
    Ryoo, Jungwoo
    Rizvi, Syed
    Aiken, William
    Kissell, John
    IEEE SECURITY & PRIVACY, 2014, 12 (06) : 68 - 74
  • [33] Revisiting the Management Control Plane in Virtualized Cloud Computing Infrastructure
    Soundararajan, Vijayaraghavan
    Spracklen, Lawrence
    2013 IEEE INTERNATIONAL SYMPOSIUM ON WORKLOAD CHARACTERIZATION (IISWC 2013), 2013, : 143 - +
  • [34] Financial Application on an Openstack Based Private Cloud
    Bajpai, Deepak
    Vinayak, Muskan
    Thulasiram, Ruppa K.
    Thulasiraman, Parimala
    INTERNET AND DISTRIBUTED COMPUTING SYSTEMS, 2018, 11226 : 109 - 121
  • [35] On the security of auditing mechanisms for secure cloud storage
    Yu, Yong
    Niu, Lei
    Yang, Guomin
    Mu, Yi
    Susilo, Willy
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2014, 30 : 127 - 132
  • [36] PROSIM in the Cloud: Remote Automation Training Platform with Virtualized Infrastructure
    Rosioru, Sabin
    Mihai, Viorel
    Neghina, Mihai
    Craciunean, Daniel
    Stamatescu, Grigore
    APPLIED SCIENCES-BASEL, 2022, 12 (06):
  • [37] Distributed High Performance Computing in OpenStack Cloud over SDN Infrastructure
    Basnet, Sadhu Ram
    Chaulagain, Ram Sharan
    Pandey, Santosh
    Shakya, Subarna
    2017 IEEE INTERNATIONAL CONFERENCE ON SMART CLOUD (SMARTCLOUD), 2017, : 144 - 148
  • [38] Towards An IoT Network Testbed Emulated over OpenStack Cloud Infrastructure
    Quan Le-Trung
    2017 INTERNATIONAL CONFERENCE ON RECENT ADVANCES IN SIGNAL PROCESSING, TELECOMMUNICATIONS & COMPUTING (SIGTELCOM), 2017, : 246 - 251
  • [39] The innovative application of cloud computing on auditing
    Huang, Shaio Yan
    Lin, Ching-Wen
    Jian, Yi-Feng
    INTERNATIONAL JOURNAL OF MOBILE COMMUNICATIONS, 2014, 12 (03) : 249 - 269
  • [40] Saudi cloud infrastructure: a security analysis
    Wahid RAJEH
    Hai JIN
    Deqing ZOU
    ScienceChina(InformationSciences), 2017, 60 (12) : 152 - 164