Insider Threats to Cloud Computing: Directions for New Research Challenges

被引:58
|
作者
Claycomb, William R. [1 ]
Nicoll, Alex [1 ]
机构
[1] Carnegie Mellon Univ, Inst Software Engn, CERT Program, Pittsburgh, PA 15213 USA
关键词
insider; cloud; security;
D O I
10.1109/COMPSAC.2012.113
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Cloud computing related insider threats are often listed as a serious concern by security researchers, but to date this threat has not been thoroughly explored. We believe the fundamental nature of current insider threats will remain relatively unchanged in a cloud environment, but the paradigm does reveal new exploit possibilities. The common notion of a cloud insider as a rogue administrator of a service provider is discussed, but we also present two additional cloud-related insider risks: the insider who exploits a cloud-related vulnerability to steal information from a cloud system, and the insider who uses cloud systems to carry out an attack on an employer's local resources. We also characterize a hierarchy of administrators within cloud service providers, give examples of attacks from real insider threat cases, and show how the nature of cloud systems architectures enables attacks to succeed. Finally, we discuss our position on future cloud research.
引用
收藏
页码:387 / 394
页数:8
相关论文
共 50 条
  • [1] A Multidimension Taxonomy of Insider Threats in Cloud Computing
    Alhanahnah, Mohannad J.
    Jhumka, Arshad
    Alouneh, Sahel
    [J]. COMPUTER JOURNAL, 2016, 59 (11): : 1612 - 1622
  • [2] Cloud Computing: A paradigm of more Insider Threats
    Bin Ahmad, Maaz
    Asif, Muhammad
    Saad, Afshan
    Wahab, Abdul
    [J]. 2019 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS ENGINEERING (ICISE 2019), 2019, : 107 - 112
  • [3] Security Threats, Defense Mechanisms, Challenges, and Future Directions in Cloud Computing
    Said El Kafhali
    Iman El Mir
    Mohamed Hanini
    [J]. Archives of Computational Methods in Engineering, 2022, 29 : 223 - 246
  • [4] Security Threats, Defense Mechanisms, Challenges, and Future Directions in Cloud Computing
    El Kafhali, Said
    El Mir, Iman
    Hanini, Mohamed
    [J]. ARCHIVES OF COMPUTATIONAL METHODS IN ENGINEERING, 2022, 29 (01) : 223 - 246
  • [5] Mobile cloud computing: Challenges and future research directions
    Noor, Talal H.
    Zeadally, Sherali
    Alfazi, Abdullah
    Sheng, Quan Z.
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2018, 115 : 70 - 85
  • [6] Cloud Computing Research Issues, Challenges, and Future Directions
    Singh, Dhirender
    Banyal, R. K.
    Sharma, Arvind Kumar
    [J]. EMERGING TRENDS IN EXPERT APPLICATIONS AND SECURITY, 2019, 841 : 617 - 623
  • [7] Mobile Cloud Computing: Challenges and Future Research Directions
    Al-Janabi, Samaher
    Al-Shourbaji, Ibrahim
    Shojafar, Mohammad
    Abdelhag, Mohammed
    [J]. 2017 10TH INTERNATIONAL CONFERENCE ON DEVELOPMENTS IN ESYSTEMS ENGINEERING (DESE 2017), 2017, : 62 - 67
  • [8] Cloud computing: Challenges and future directions
    Choo, Kim-Kwang
    [J]. TRENDS AND ISSUES IN CRIME AND CRIMINAL JUSTICE, 2010, (400):
  • [9] Cloud Computing Security Challenges, Threats and Vulnerabilities
    Sasubilli, Manoj Kumar
    Venkateswarlu, R.
    [J]. PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON INVENTIVE COMPUTATION TECHNOLOGIES (ICICT 2021), 2021, : 476 - 480
  • [10] Next generation cloud computing: New trends and research directions
    Varghese, Blesson
    Buyya, Rajkumar
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 79 : 849 - 861