Making Least Privilege the Low-Hanging Fruit in Clouds

被引:0
|
作者
Tian Puyang
Shen, Qingni [1 ]
Luo, Yang
Luo, Wu
Wu, Zhonghai
机构
[1] Peking Univ, Sch Software & Microelect, Beijing, Peoples R China
[2] Peking Univ, Natl Engn Ctr Software Engn, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Failing to promote the least privilege principle in administration can lead to substantial vulnerabilities in cloud computing. A malicious insider like a compromised cloud administrator can affect security of data and workloads belonging to cloud customers. Enforcing the least privilege principle in cloud administration can fairly restrict the permissions of administrators and reduce the attack surface. However, writing a least privilege policy can be hard and error prone for cloud service providers. In this paper, we propose a framework called Least Privilege for Cloud (LPCloud) to address these concerns. LPCloud automatically produces policies for minimization of administrators' privileges at the granularity of representational state transfer (REST) application program interfaces (API), and enforces the policies without affecting current systems. Specifically, we introduce a novel algorithm to partition privileges based on dependencies between API calls. This paper presents design of LPCloud, including a service called Policy Generator which produces partitioned policies and a component named Policy Enforcer to enforce the policies. We implement a prototype of our framework in OpenStack Mitaka. Experiments indicate that LPCloud can produce proper policies to enforce the least privilege principle. Meantime, the average performance overhead is 10.1% which is in acceptable level.
引用
收藏
页数:7
相关论文
共 50 条
  • [31] Pharmacogenomics: the low-hanging fruit in the personalized medicine tree
    Patrinos, George P.
    Shuldiner, Alan R.
    [J]. HUMAN GENETICS, 2022, 141 (06) : 1109 - 1111
  • [32] Directed enzyme evolution: beyond the low-hanging fruit
    Goldsmith, Moshe
    Tawfik, Dan S.
    [J]. CURRENT OPINION IN STRUCTURAL BIOLOGY, 2012, 22 (04) : 406 - 412
  • [33] SANDIAS PEERCY ON CFM, CVD, AND LOW-HANGING FRUIT
    DEERCY, P
    [J]. MICROCONTAMINATION, 1994, 12 (10): : 12 - &
  • [34] Physiology and assessment as low-hanging fruit for education overhaul
    Ribeiro S.
    Mota N.B.
    Fernandes V.R.
    Deslandes A.C.
    Brockington G.
    Copelli M.
    [J]. PROSPECTS, 2016, 46 (2) : 249 - 264
  • [35] Survival and neurological outcome: Search for a low-hanging fruit
    Bjorshol, Conrad Arnfinn
    Kramer-Johansen, Jo
    [J]. RESUSCITATION, 2020, 148 : 269 - 270
  • [36] Added Sugar Labeling The Low-Hanging Fruit for Cardiometabolic Disease Prevention Policy-Making
    Magnuson, Elizabeth A.
    Chan, Paul S.
    [J]. CIRCULATION, 2019, 139 (23) : 2625 - 2627
  • [37] Mental Health in ACOs: Missed Opportunities and Low-Hanging Fruit
    O'Donnell, Allison N.
    Williams, Brent C.
    Eisenberg, Daniel
    Kilbourne, Amy M.
    [J]. AMERICAN JOURNAL OF MANAGED CARE, 2013, 19 (03): : 180 - 184
  • [38] More Low-Hanging Fruit: A Call for Technology for Distracted Driving
    Jividen, Maria
    Scherer, William T.
    Smith, Michael C.
    [J]. IEEE INTELLIGENT TRANSPORTATION SYSTEMS MAGAZINE, 2009, 1 (04) : 4 - 7
  • [39] Reaching beyond low-hanging fruit: Basic research and innovativeness
    Ceccagnoli, Marco
    Lee, You-Na
    Walsh, John P.
    [J]. RESEARCH POLICY, 2024, 53 (01)
  • [40] Low-Hanging Fruit: The Impoverished History of Housing and School Desegregation
    Bonastia, Christopher
    [J]. SOCIOLOGICAL FORUM, 2015, 30 : 549 - 570