Security and Privacy Preservation of Evidence in Cloud Accountability Audits

被引:2
|
作者
Ruebsamen, Thomas [1 ]
Pulls, Tobias [2 ]
Reich, Christoph [1 ]
机构
[1] Furtwangen Univ, Cloud Res Lab, Furtwangen, Germany
[2] Karlstad Univ, Dept Math & Comp Sci, Karlstad, Sweden
关键词
D O I
10.1007/978-3-319-29582-4_6
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Cloud accountability audits are promising to strengthen trust in cloud computing by providing reassurance about the processing data in the cloud according to data handling and privacy policies. To effectively automate cloud accountability audits, various distributed evidence sources need to be considered during evaluation. The types of information range from authentication and data access logging to location information, information on security controls and incident detection. Securing that information quickly becomes a challenge in the system design, when the evidence that is needed for the audit is deemed sensitive or confidential information. This means that securing the evidence at-rest as well as in-transit is of utmost importance. In this paper, we present a system that is based on distributed software agents which enables secure evidence collection with the purpose of automated evaluation during cloud accountability audits. We thereby present the integration of Insynd as a suitable cryptographic mechanism for securing evidence. We present our reasoning for choosing Insynd by showing a comparison of Insynd properties with requirements imposed by accountability evidence collection as well as an analysis how security threats are being mitigated by Insynd. We put special emphasis on security and privacy protection in our system analysis.
引用
收藏
页码:95 / 114
页数:20
相关论文
共 50 条
  • [1] Privacy Risk, Security, Accountability in the Cloud
    Theoharidou, Marianthi
    Papanikolaou, Nick
    Pearson, Siani
    Gritzalis, Dimitris
    2013 IEEE FIFTH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), VOL 1, 2013, : 177 - 184
  • [2] Cloud Audits and Privacy Risks
    Ruebsamen, Thomas
    Reich, Christoph
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS: OTM 2013 CONFERENCES, 2013, 8185 : 403 - 413
  • [3] Security and Privacy Preservation of Electronic Health Records in Cloud
    Sharma, Smita
    Tyagi, Sanjay
    INTERNATIONAL JOURNAL OF FUZZY LOGIC AND INTELLIGENT SYSTEMS, 2024, 24 (04) : 428 - 439
  • [4] Ensuring Security and Privacy Preservation for Cloud Data Services
    Tang, Jun
    Cui, Yong
    Li, Qi
    Ren, Kui
    Liu, Jiangchuan
    Buyya, Rajkumar
    ACM COMPUTING SURVEYS, 2016, 49 (01)
  • [5] A Comprehensive Review on Security and Privacy Preservation in Cloud Environment
    Bingu, Rajesh
    Jothilakshmi, S.
    Srinivasu, N.
    SUSTAINABLE COMMUNICATION NETWORKS AND APPLICATION, ICSCN 2021, 2022, 93 : 719 - 738
  • [6] Data Sharing Security and Privacy Preservation in Cloud Computing
    Prasad, Kadam
    Poonam, Jadhav
    Gauri, Khupase
    Thoutam, N. C.
    2015 INTERNATIONAL CONFERENCE ON GREEN COMPUTING AND INTERNET OF THINGS (ICGCIOT), 2015, : 1070 - 1075
  • [7] Enhanced Privacy Preservation and Data Storage Security in Public Cloud
    Deshmukh, Rachana
    Deshmukh, Rashmi
    Chaudhari, Pallavi
    HELIX, 2018, 8 (05): : 3726 - 3730
  • [8] Cloud Security and Privacy Metamodel Metamodel for Security and Privacy Knowledge in Cloud Services
    Xia, Tian
    Washizaki, Hironori
    Kato, Takehisa
    Kaiya, Haruhiko
    Ogata, Shinpei
    Fernandez, Eduardo B.
    Kanuka, Hideyuki
    Yoshino, Masayuki
    Yamamoto, Dan
    Okubo, Takao
    Yoshioka, Nobukazu
    Hazeyama, Atsuo
    PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON MODEL-DRIVEN ENGINEERING AND SOFTWARE DEVELOPMENT, 2018, : 379 - 386
  • [9] Enhanced Honeypot cryptographic scheme and privacy preservation for an effective prediction in cloud security
    Mondal, Avijit
    Goswami, Radha Tamal
    MICROPROCESSORS AND MICROSYSTEMS, 2021, 81
  • [10] Data security and privacy preservation in cloud storage environments based on cryptographic mechanisms
    Kaaniche, Nesrine
    Laurent, Maryline
    COMPUTER COMMUNICATIONS, 2017, 111 : 120 - 141