ITADP: An inter-tenant attack detection and prevention framework for multi-tenant SaaS

被引:3
|
作者
Yassin, Mohamed [1 ]
Talhi, Chamseddine [2 ]
Boucheneb, Hanifa [1 ]
机构
[1] Polytech Montreal, Montreal, PQ, Canada
[2] Ecole Technol Super, Montreal, PQ, Canada
关键词
SaaS; Multi-tenant; Detection; Prevention; Inter-tenant attack; SERVICE DELIVERY MODELS; SECURITY ISSUES;
D O I
10.1016/j.jisa.2019.102395
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-as-a-service (SaaS) is a service-oriented Web application running on a Cloud environment. With the multi-tenancy, the SaaS provider can largely reduce the cost of resources and maintenance by sharing the application and database instances between its tenants (clients). This multi-tenancy affects the security of tenants, specifically, when several tenants use the same tables of a single database. Indeed, an important consequence of this full multi-tenancy is that a malicious tenant user can view or modify the rows of other tenants. Consequently, the detection and prevention of attacks among tenants is a key security requirement that should be addressed by the provider. In this sense, this paper proposes an intertenant attack detection and prevention framework, based on SQL syntactic analysis, for multi-tenant SaaS. This framework is integrated in Amazon Web Services (AWS) public Cloud and meets accuracy, portability, compatibility, and ease of integration requirements. The experiment results show that the framework works with small overhead on the virtual machines and minimal impact on the HTTP response time. (C) 2019 Elsevier Ltd. All rights reserved.
引用
下载
收藏
页数:15
相关论文
共 50 条
  • [1] Multi-Tenant Intrusion Detection Framework as a Service for SaaS
    Yassin, Mohamed
    Ould-Slimane, Hakima
    Talhi, Chamseddine
    Boucheneb, Hanifa
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2022, 15 (05) : 2925 - 2938
  • [2] Multi-tenant SaaS Cloud
    Kulkarni, Gurudatt
    Khatawkar, Prasad
    Shelke, Rupali
    Solanke, Vikas
    Waghmare, Rani
    AFRICON, 2013, 2013,
  • [3] Multi-tenant SaaS Cloud
    Kulkarni, Gurudatt
    Shelke, Rupali
    Palwe, Rajnikant
    Khatawkar, Prasad
    Bhuse, Sadanand
    Bankar, Hemant
    2013 FOURTH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATIONS AND NETWORKING TECHNOLOGIES (ICCCNT), 2013,
  • [4] SaaS Multi-Tenant Application Customization
    Tsai, Wei-Tek
    Sun, Xin
    2013 IEEE SEVENTH INTERNATIONAL SYMPOSIUM ON SERVICE-ORIENTED SYSTEM ENGINEERING (SOSE 2013), 2013, : 1 - 12
  • [5] A Framework of Scaling for Inter-tenant Collaborative Systems
    Liang, Qianhui
    Zhao, Guopeng
    Gioachin, Filippo
    Chang, Sau Sheong
    2012 IEEE 4TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), 2012,
  • [6] Design and Implementation of a Cloud SaaS Framework for Multi-Tenant Applications
    Morakos, Petros
    Meliones, Apostolos
    5TH INTERNATIONAL CONFERENCE ON INFORMATION, INTELLIGENCE, SYSTEMS AND APPLICATIONS, IISA 2014, 2014, : 273 - 278
  • [7] Multi-tenant data authentication model for SaaS
    Li, Lin
    Kong, Lanju
    Li, Qingzhong
    Yan, Zhongmin
    Li, Hui
    Open Cybernetics and Systemics Journal, 2014, 8 (01): : 322 - 329
  • [9] Modeling and Analysis of Availability in Multi-tenant SaaS
    Su, Wenbo
    Liu, Qu
    Lin, Chuang
    Shen, Sherman
    24TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS ICCCN 2015, 2015,
  • [10] Multi-tenant data authentication model for SaaS
    Li, Qingzhong (lqz@sdu.edu.cn), 1600, Bentham Science Publishers B.V., P.O. Box 294, Bussum, 1400 AG, Netherlands (08):