Making Least Privilege the Low-Hanging Fruit in Clouds

被引:0
|
作者
Tian Puyang
Shen, Qingni [1 ]
Luo, Yang
Luo, Wu
Wu, Zhonghai
机构
[1] Peking Univ, Sch Software & Microelect, Beijing, Peoples R China
[2] Peking Univ, Natl Engn Ctr Software Engn, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Failing to promote the least privilege principle in administration can lead to substantial vulnerabilities in cloud computing. A malicious insider like a compromised cloud administrator can affect security of data and workloads belonging to cloud customers. Enforcing the least privilege principle in cloud administration can fairly restrict the permissions of administrators and reduce the attack surface. However, writing a least privilege policy can be hard and error prone for cloud service providers. In this paper, we propose a framework called Least Privilege for Cloud (LPCloud) to address these concerns. LPCloud automatically produces policies for minimization of administrators' privileges at the granularity of representational state transfer (REST) application program interfaces (API), and enforces the policies without affecting current systems. Specifically, we introduce a novel algorithm to partition privileges based on dependencies between API calls. This paper presents design of LPCloud, including a service called Policy Generator which produces partitioned policies and a component named Policy Enforcer to enforce the policies. We implement a prototype of our framework in OpenStack Mitaka. Experiments indicate that LPCloud can produce proper policies to enforce the least privilege principle. Meantime, the average performance overhead is 10.1% which is in acceptable level.
引用
收藏
页数:7
相关论文
共 50 条
  • [1] Low-hanging fruit
    Burkgren, Tom
    [J]. JOURNAL OF SWINE HEALTH AND PRODUCTION, 2012, 20 (01): : 7 - 7
  • [2] Low-hanging fruit
    Behrens, Edward
    [J]. APOLLO-THE INTERNATIONAL ART MAGAZINE, 2024, 199 (727): : 13 - 13
  • [3] Grab the low-hanging fruit
    Rosenburg, Y
    [J]. FORTUNE, 2004, 149 (08) : 142 - 142
  • [4] Perceptual Decision-Making: Picking the Low-Hanging Fruit?
    de Lange, Floris P.
    Fritsche, Matthias
    [J]. TRENDS IN COGNITIVE SCIENCES, 2017, 21 (05) : 306 - 307
  • [5] TARGETING THE LOW-HANGING FRUIT OF NEURODEGENERATION
    Mason, Amanda R.
    Ziemann, Adam
    Finkbeiner, Steven
    [J]. NEUROLOGY, 2014, 83 (16) : 1470 - 1473
  • [6] Kyoto's low-hanging fruit
    Voith, Melody
    [J]. CHEMICAL & ENGINEERING NEWS, 2008, 86 (27) : 17 - 17
  • [7] State funding is not "low-hanging fruit"
    Miller, Rebecca T.
    [J]. LIBRARY JOURNAL, 2015, 140 (09) : 8 - 8
  • [8] Low-hanging fruit: targeting Brdt in the testes
    Bryant, Jessica M.
    Berger, Shelley L.
    [J]. EMBO JOURNAL, 2012, 31 (19): : 3788 - 3789
  • [9] Generalizability The trees, the forest, and the low-hanging fruit
    Kukull, Walter A.
    Ganguli, Mary
    [J]. NEUROLOGY, 2012, 78 (23) : 1886 - 1891
  • [10] Individual carbon emissions: The low-hanging fruit
    Vandenbergh, Michael P.
    Barkenbus, Jack
    Gilligan, Jonathan
    [J]. UCLA LAW REVIEW, 2008, 55 (06) : 1701 - 1758