首页> 外文期刊>International Journal of Information Security >Security policy verification for multi-domains in cloud systems
【24h】

Security policy verification for multi-domains in cloud systems

机译:云系统中多域的安全策略验证

获取原文
获取原文并翻译 | 示例
           

摘要

The cloud is a modern computing paradigm with the ability to support a business model by providing multi-tenancy, scalability, elasticity, pay as you go and selfprovisioning of resources by using broad network access.Yet, cloud systems are mostly bounded to single domains, and collaboration among different cloud systems is an active area of research. Over time, such collaboration schemas are becoming of vital importance since they allow companies to diversify their services on multiple cloud systems to increase both uptime and usage of services. The existence of an efficient management process for the enforcement of security policies among the participating cloud systems would facilitate the adoption of multi-domain cloud systems. An important issue in collaborative environments is secure inter-operation. Stemmed from the absence of relevant work in the area of cloud computing, we define a model checking technique that can be used as a management service/tool for the verification of multi-domain cloud policies. Our proposal is based on NIST’s (National Institute of Standards and Technology) generic model checking technique and has been enriched with RBAC reasoning. Current approaches, in Grid systems, are capable of verifying and detect only conflicts and redundancies between two policies. However, the latter cannot overcome the risk of privileged user access in multi-domain cloud systems. In this paper, we provide the formal definition of the proposed technique and security properties that have to be verified in multi-domain cloud systems. Furthermore, an evaluation of the technique through a series of performance tests is provided.
机译:云是一种现代计算范例,能够通过提供多租户,可扩展性,弹性,随用随付以及通过使用广泛的网络访问来进行资源自配置来支持业务模型。然而,云系统大多限于单个域,不同云系统之间的协作是一个活跃的研究领域。随着时间的流逝,这种协作模式变得至关重要,因为它们允许公司在多个云系统上分散其服务,以增加正常运行时间和服务使用率。在参与的云系统之间存在用于实施安全策略的有效管理流程,将有助于采用多域云系统。协作环境中的一个重要问题是安全的互操作。出于缺乏云计算领域相关工作的限制,我们定义了一种模型检查技术,该技术可以用作管理服务/工具来验证多域云策略。我们的建议基于NIST(美国国家标准技术研究院)的通用模型检查技术,并且已经丰富了RBAC推理功能。网格系统中的当前方法仅能够验证和检测两个策略之间的冲突和冗余。但是,后者无法克服多域云系统中特权用户访问的风险。在本文中,我们提供了必须在多域云系统中进行验证的拟议技术和安全属性的正式定义。此外,通过一系列性能测试提供了对该技术的评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号