An Effective Auditing Scheme for Cloud Computing

被引:0
|
作者
Houlihan, Ryan [1 ]
Du, Xiaojiang [1 ]
机构
[1] Temple Univ, Dept Comp & Informat Sci, Philadelphia, PA 19122 USA
关键词
Cloud computing; performance; auditing;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
In this paper, we present a novel secure auditing scheme for cloud computing systems. Several auditing schemes have been proposed for the cloud, which periodically trigger the auditing function. These schemes are designed to monitor the performance and behavior of the cloud. One major problem with these kind of schemes is that they are vulnerable to the transient attack (also known as the timed scrubbing attack). Our secure auditing scheme is able to prevent the transient attack via modification of the Linux auditing daemon - auditd, which creates attestable logs. Our scheme utilizes the System Management Mode (SMM) for integrity checks and the Trusted Platform Module (TPM) chip for attestable security. Specifically, we modify the auditing daemon protocol such that it records a hash of each audit log entry to the TPM's Platform Configuration Register (PCR), which gives us an attestable history of every command executed on the cloud server. We perform real experiments on two cloud servers and the results show that the overhead of our scheme is very small.
引用
收藏
页码:1599 / 1604
页数:6
相关论文
共 50 条
  • [1] Effective Third Party Auditing in Cloud Computing
    Hussain, Mohammed
    Al-Mourad, Mohamed Basel
    [J]. 2014 28TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS (WAINA), 2014, : 91 - 95
  • [2] An Improved Secure Public Cloud Auditing Scheme in Edge Computing
    Yi, Zhengge
    Wei, Lixian
    Yang, Haibin
    Wang, Xu An
    Yuan, Wenyong
    Li, Ruifeng
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [3] Public Auditing Scheme for Data Storage Security in Cloud Computing
    Subha, T.
    Jayashri, S.
    [J]. JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2017, 33 (03) : 773 - 787
  • [4] Auditing Cloud Computing Migration
    Mateescu, Georgiana
    Vladescu, Marius
    Sgarciu, Valentin
    [J]. 2014 IEEE 9TH INTERNATIONAL SYMPOSIUM ON APPLIED COMPUTATIONAL INTELLIGENCE AND INFORMATICS (SACI), 2014, : 263 - 268
  • [5] Decentralized Integrity Auditing Scheme for Cloud Data Based on Blockchain and Edge Computing
    Yang, Xiaodong
    Wang, Xiuxiu
    Li, Xixi
    Zhou, Hang
    Wang, Caifen
    [J]. Dianzi Yu Xinxi Xuebao/Journal of Electronics and Information Technology, 2023, 45 (10): : 3759 - 3766
  • [6] An Authorized Public Auditing Scheme for Dynamic Big Data Storage in Cloud Computing
    Yu, Han
    Lu, Xiuqing
    Pan, Zhenkuan
    [J]. IEEE ACCESS, 2020, 8 : 151465 - 151473
  • [7] Efficient Auditing Scheme for Secure Data Storage in Fog-to-Cloud Computing
    Zhang, Xingjun
    Si, Wei
    [J]. IEEE ACCESS, 2021, 9 : 37951 - 37960
  • [8] A Cost Effective Dynamic Auditing Scheme for Outsourced Data Storage in Cloud Environment
    Daniel, Esther
    Vasanthi, N. A.
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON INNOVATIONS IN GREEN ENERGY AND HEALTHCARE TECHNOLOGIES (IGEHT), 2017,
  • [9] Auditing in Cloud Computing Solutions with OpenStack
    Konoor, Divya K.
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING IN EMERGING MARKETS (CCEM), 2016, : 176 - 176
  • [10] The innovative application of cloud computing on auditing
    Huang, Shaio Yan
    Lin, Ching-Wen
    Jian, Yi-Feng
    [J]. INTERNATIONAL JOURNAL OF MOBILE COMMUNICATIONS, 2014, 12 (03) : 249 - 269