ITADP: An inter-tenant attack detection and prevention framework for multi-tenant SaaS

被引:3
|
作者
Yassin, Mohamed [1 ]
Talhi, Chamseddine [2 ]
Boucheneb, Hanifa [1 ]
机构
[1] Polytech Montreal, Montreal, PQ, Canada
[2] Ecole Technol Super, Montreal, PQ, Canada
关键词
SaaS; Multi-tenant; Detection; Prevention; Inter-tenant attack; SERVICE DELIVERY MODELS; SECURITY ISSUES;
D O I
10.1016/j.jisa.2019.102395
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-as-a-service (SaaS) is a service-oriented Web application running on a Cloud environment. With the multi-tenancy, the SaaS provider can largely reduce the cost of resources and maintenance by sharing the application and database instances between its tenants (clients). This multi-tenancy affects the security of tenants, specifically, when several tenants use the same tables of a single database. Indeed, an important consequence of this full multi-tenancy is that a malicious tenant user can view or modify the rows of other tenants. Consequently, the detection and prevention of attacks among tenants is a key security requirement that should be addressed by the provider. In this sense, this paper proposes an intertenant attack detection and prevention framework, based on SQL syntactic analysis, for multi-tenant SaaS. This framework is integrated in Amazon Web Services (AWS) public Cloud and meets accuracy, portability, compatibility, and ease of integration requirements. The experiment results show that the framework works with small overhead on the virtual machines and minimal impact on the HTTP response time. (C) 2019 Elsevier Ltd. All rights reserved.
引用
下载
收藏
页数:15
相关论文
共 50 条
  • [21] A Process Model for Customisation of Software in Multi-Tenant SaaS Model
    Khan, Khaled M.
    Nhlabatsi, Armstrong
    Khan, Niamul
    2015 IEEE/ACM 8TH INTERNATIONAL CONFERENCE ON UTILITY AND CLOUD COMPUTING (UCC), 2015, : 418 - 419
  • [22] Dynamic Provisioning of Service Composition in a Multi-Tenant SaaS Environment
    Wael Sellami
    Hatem Hadj Kacem
    Ahmed Hadj Kacem
    Journal of Network and Systems Management, 2020, 28 : 367 - 397
  • [23] Multi-tenant Quality Attributes to Manage Tenants in SaaS Applications
    Kalra, Sumit
    Prabhakar, T., V
    2020 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ARCHITECTURE COMPANION (ICSA-C 2020), 2020, : 83 - 88
  • [24] Suitable Database Development Framework for Business Component Migration in SaaS Multi-tenant Model
    Zhou, Xuequan
    Zhan, Dechen
    Nie, Lanshun
    Meng, Fanchao
    Xu, Xiaofei
    2013 INTERNATIONAL CONFERENCE ON SERVICE SCIENCES (ICSS 2013), 2013, : 90 - 95
  • [25] WFFS: A SaaS-Based Multi-tenant Workflow Engine
    Lv, Bingcai
    Zhang, Shidong
    Liu, Zhengzheng
    Kong, Lanju
    EMERGING COMPUTATION AND INFORMATION TECHNOLOGIES FOR EDUCATION, 2012, 146 : 77 - +
  • [26] Software Architecture Driven Configurability of Multi-tenant SaaS Application
    Wang, Hua
    Zheng, Zhijun
    WEB INFORMATION SYSTEMS AND MINING, 2010, 6318 : 418 - 424
  • [27] Deep Customization of Multi-Tenant SaaS Using Intrusive Microservices
    Song, Hui
    Chauvel, Franck
    Solberg, Arnor
    2018 IEEE/ACM 40TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: NEW IDEAS AND EMERGING TECHNOLOGIES RESULTS (ICSE-NIER), 2018, : 97 - 100
  • [28] A Multi-Tenant Level Lightweight Lock Mechanism for Multi-Tenant Database
    Kang, Tao
    Zhang, Shidong
    Kong, Lanju
    2014 11th Web Information System and Application Conference (WISA), 2014, : 3 - 7
  • [29] SignedQuery: Protecting Users Data in Multi-tenant SaaS Environments
    Saleh, Eyad
    Takouna, Ibrahim
    Meinel, Christoph
    2013 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2013, : 213 - 218
  • [30] Dynamic Provisioning of Service Composition in a Multi-Tenant SaaS Environment
    Sellami, Wael
    Kacem, Hatem
    Kacem, Ahmed
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2020, 28 (02) : 367 - 397