ITADP: An inter-tenant attack detection and prevention framework for multi-tenant SaaS

被引:4
|
作者
Yassin, Mohamed [1 ]
Talhi, Chamseddine [2 ]
Boucheneb, Hanifa [1 ]
机构
[1] Polytech Montreal, Montreal, PQ, Canada
[2] Ecole Technol Super, Montreal, PQ, Canada
关键词
SaaS; Multi-tenant; Detection; Prevention; Inter-tenant attack; SERVICE DELIVERY MODELS; SECURITY ISSUES;
D O I
10.1016/j.jisa.2019.102395
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-as-a-service (SaaS) is a service-oriented Web application running on a Cloud environment. With the multi-tenancy, the SaaS provider can largely reduce the cost of resources and maintenance by sharing the application and database instances between its tenants (clients). This multi-tenancy affects the security of tenants, specifically, when several tenants use the same tables of a single database. Indeed, an important consequence of this full multi-tenancy is that a malicious tenant user can view or modify the rows of other tenants. Consequently, the detection and prevention of attacks among tenants is a key security requirement that should be addressed by the provider. In this sense, this paper proposes an intertenant attack detection and prevention framework, based on SQL syntactic analysis, for multi-tenant SaaS. This framework is integrated in Amazon Web Services (AWS) public Cloud and meets accuracy, portability, compatibility, and ease of integration requirements. The experiment results show that the framework works with small overhead on the virtual machines and minimal impact on the HTTP response time. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页数:15
相关论文
共 50 条
  • [41] Event-Based Customization of Multi-tenant SaaS Using Microservices
    Nordli, Espen Tonnessen
    Nguyen, Phu H.
    Chauvel, Franck
    Song, Hui
    COORDINATION MODELS AND LANGUAGES, COORDINATION 2020, 2020, 12134 : 171 - 180
  • [42] Multi-tenant SaaS deployment optimisation algorithm for cloud computing environment
    Cao Ming
    Yu Bingjie
    Liu Xiantong
    INTERNATIONAL JOURNAL OF INTERNET PROTOCOL TECHNOLOGY, 2018, 11 (03) : 152 - 158
  • [43] QoS-Aware Service Recommendation for Multi-Tenant SaaS on the Cloud
    Wang, Yanchun
    He, Qiang
    Yang, Yun
    2015 IEEE 12TH INTERNATIONAL CONFERENCE ON SERVICES COMPUTING (SCC 2015), 2015, : 178 - 185
  • [44] Lightweight Monitoring Scheme for Flooding DoS Attack Detection in Multi-Tenant MPSoCs
    Chaves, Cesar G.
    Sepulveda, Johanna
    Hollstein, Thomas
    2021 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS (ISCAS), 2021,
  • [45] Using Microservices for Non-intrusive Customization of Multi-tenant SaaS
    Nguyen, Phu H.
    Song, Hui
    Chauvel, Franck
    Muller, Roy
    Boyar, Seref
    Levin, Erik
    ESEC/FSE'2019: PROCEEDINGS OF THE 2019 27TH ACM JOINT MEETING ON EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING, 2019, : 905 - 915
  • [46] Towards a container-based architecture for multi-tenant SaaS applications
    Truyen, Eddy
    Van Landuyt, Dimitri
    Reniers, Vincent
    Rafique, Ansar
    Lagaisse, Bert
    Joosen, Wouter
    15TH WORKSHOP ON ADAPTIVE AND REFLECTIVE MIDDLEWARE (ARM 2016), 2016,
  • [47] Research on Optimization Adjustment Strategy for SaaS Multi-tenant Data Placement
    Li Xiaona
    Li Qingzhong
    Zhu Weiyi
    Li Hui
    INTERNATIONAL JOURNAL OF GRID AND DISTRIBUTED COMPUTING, 2015, 8 (02): : 319 - 330
  • [48] Enhanced Scaffold Design Pattern for Seculde Multi-tenant SaaS Application
    Balasubramanian, Nagarajan
    Jayapal, Suguna
    PROCEEDINGS OF THE FIRST INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND INFORMATICS, ICCII 2016, 2017, 507 : 671 - 680
  • [49] Policy-Driven Middleware for Multi-Tenant SaaS Services Configuration
    Aouzal, Khadija
    Hafiddi, Hatim
    Dahchour, Mohamed
    INTERNATIONAL JOURNAL OF CLOUD APPLICATIONS AND COMPUTING, 2019, 9 (04) : 86 - 106
  • [50] Runtime Evolution of Service-Based Multi-tenant SaaS Applications
    Kumara, Indika
    Han, Jun
    Colman, Alan
    Kapuruge, Malinda
    SERVICE-ORIENTED COMPUTING, ICSOC 2013, 2013, 8274 : 192 - 206