Network-level Access Control Management for the Cloud

被引:5
|
作者
Beaty, Kirk [1 ]
Kundu, Ashish [1 ]
Naik, Vijay [1 ]
Acharya, Arup [1 ]
机构
[1] IBM TJ Watson Res Ctr, Hawthorne, NY 10532 USA
关键词
D O I
10.1109/IC2E.2013.18
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
One of the major security threats that public cloud computing platforms face today is that the active cloud virtual machine instances are visible and accessible via the public internet, which allows hackers to carry out several types of attacks such as Denial of Service (DoS) and intrusion over a long durations which increases the probabilities of successful penetration. Security logs of the failed attempts attest to the real threat and the intensity and duration of these. Most systems running on public cloud instances today are not security-hardened to withstand such persistent and long attacks. It is not only dangerous but also disastrous for the enterprise that uses such instances to deliver cloud services, for the users that use such services, and for the cloud provider that provides the cloud infrastructure. Therefore, what is required is a network-level access control solution that facilitates delivery of cloud services while protecting the network perimeter of the solution in a useable and dynamically customizable manner. In this paper, we have described such a network-based access control solution for public cloud services that we have designed and developed and is applicable to any of the various cloud platforms available today. We have deployed our solution as part of the "Security-as-a-Service" model on IBM Smart Cloud Enterprise (SCE), and has been used for commercial delivery of cloud services. These applications have led to not only high level of security with no security attacks via network exposure on the services, but also significant savings on the cost of maintaining the security of such instances and services. We have also studied the challenges that network address translators (NATs) pose for network-based access control on public cloud, and have developed solutions for such challenges.
引用
收藏
页码:98 / 107
页数:10
相关论文
共 50 条
  • [1] Network-Level Access Control Policy Analysis and Transformation
    Basile, Cataldo
    Cappadonia, Alberto
    Lioy, Antonio
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2012, 20 (04) : 985 - 998
  • [2] History based distributed filtering - A tagging approach to network-level access control
    Sailer, R
    Kabatnik, M
    [J]. 16TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2000, : 373 - 382
  • [3] Towards Network-level Efficiency for Cloud Storage Services
    Li, Zhenhua
    Jin, Cheng
    Xu, Tianyin
    Wilson, Christo
    Liu, Yao
    Cheng, Linsong
    Liu, Yunhao
    Dai, Yafei
    Zhang, Zhi-Li
    [J]. PROCEEDINGS OF THE 2014 ACM INTERNET MEASUREMENT CONFERENCE (IMC'14), 2014, : 115 - 128
  • [4] Twofold control loop network-level congestion control
    Calvagna, Andrea
    Tropea, Giuseppe
    [J]. EUROPEAN TRANSACTIONS ON TELECOMMUNICATIONS, 2007, 18 (01): : 81 - 95
  • [5] Network-level Cooperation in Random Access IoT Networks with Aggregators
    Pappas, Nikolaos
    Dimitriou, Ioannis
    Chen, Zheng
    [J]. PROCEEDINGS OF THE 2018 30TH INTERNATIONAL TELETRAFFIC CONGRESS (ITC 30), VOL 1, 2018, : 245 - 253
  • [6] GIS applications for maintenance management of network-level bridges
    Liu, CL
    Hammad, A
    Itoh, Y
    [J]. STRUCTURAL SAFETY AND RELIABILITY, VOLS. 1-3, 1998, : 237 - 244
  • [7] Network-Level Railway Track Maintenance Management Model
    Burrow, M. P. N.
    Naito, S.
    Evdorides, H. T.
    [J]. TRANSPORTATION RESEARCH RECORD, 2009, (2117) : 66 - 76
  • [8] Multicriteria optimization method for network-level bridge management
    Rensselaer Polytechnic Inst, Troy, United States
    [J]. Transp Res Rec, 1561 (37-43):
  • [9] Network-level loss control schemes for streaming video
    Bai, Y
    Ito, MR
    [J]. 2004 IEEE INTERNATIONAL CONFERENCE ON MULTIMEDIA AND EXP (ICME), VOLS 1-3, 2004, : 495 - 498
  • [10] Network-Level Control of Frequency Tuning in Auditory Cortex
    Kato, Hiroyuki K.
    Asinof, Samuel K.
    Isaacson, Jeffry S.
    [J]. NEURON, 2017, 95 (02) : 412 - +