ITADP: An inter-tenant attack detection and prevention framework for multi-tenant SaaS

被引:3
|
作者
Yassin, Mohamed [1 ]
Talhi, Chamseddine [2 ]
Boucheneb, Hanifa [1 ]
机构
[1] Polytech Montreal, Montreal, PQ, Canada
[2] Ecole Technol Super, Montreal, PQ, Canada
关键词
SaaS; Multi-tenant; Detection; Prevention; Inter-tenant attack; SERVICE DELIVERY MODELS; SECURITY ISSUES;
D O I
10.1016/j.jisa.2019.102395
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-as-a-service (SaaS) is a service-oriented Web application running on a Cloud environment. With the multi-tenancy, the SaaS provider can largely reduce the cost of resources and maintenance by sharing the application and database instances between its tenants (clients). This multi-tenancy affects the security of tenants, specifically, when several tenants use the same tables of a single database. Indeed, an important consequence of this full multi-tenancy is that a malicious tenant user can view or modify the rows of other tenants. Consequently, the detection and prevention of attacks among tenants is a key security requirement that should be addressed by the provider. In this sense, this paper proposes an intertenant attack detection and prevention framework, based on SQL syntactic analysis, for multi-tenant SaaS. This framework is integrated in Amazon Web Services (AWS) public Cloud and meets accuracy, portability, compatibility, and ease of integration requirements. The experiment results show that the framework works with small overhead on the virtual machines and minimal impact on the HTTP response time. (C) 2019 Elsevier Ltd. All rights reserved.
引用
下载
收藏
页数:15
相关论文
共 50 条
  • [31] Middleware for Dynamic Upgrade Activation and Compensations in Multi-tenant SaaS
    Van Landuyt, Dimitri
    Gey, Fatih
    Truyen, Eddy
    Joosen, Wouter
    SERVICE-ORIENTED COMPUTING, ICSOC 2017, 2017, 10601 : 340 - 348
  • [32] A Multi-Tenant Framework for Multimedia Conference System
    Wang Shaofeng
    Shang Yanlei
    Tian Yue
    2013 8TH INTERNATIONAL ICST CONFERENCE ON COMMUNICATIONS AND NETWORKING IN CHINA (CHINACOM), 2013, : 161 - 165
  • [33] Framework for Management of Multi-tenant Cloud Environments
    Beranek, Marek
    Kovar, Vladimir
    Feuerlicht, George
    CLOUD COMPUTING - CLOUD 2018, 2018, 10967 : 309 - 322
  • [34] A Multi-Tenant Framework for Cloud Container Services
    Zheng, Chao
    Zhuang, Qinghui
    Guo, Fei
    2021 IEEE 41ST INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS 2021), 2021, : 359 - 369
  • [35] Design and development of multi-tenant web framework
    Kuppusamy, Sivakumar
    Thirupathi, Devi
    Kaniappan, Vivekanandan
    INTERNATIONAL JOURNAL OF SERVICES TECHNOLOGY AND MANAGEMENT, 2018, 24 (1-3) : 230 - 245
  • [36] Evolving Multi-tenant SaaS Applications through Self-Adaptive Upgrade Enactment and Tenant Mediation
    Gey, Fatih
    Van Landuyt, Dimitri
    Joosen, Wouter
    PROCEEDINGS OF 2016 IEEE/ACM 11TH INTERNATIONAL SYMPOSIUM ON SOFTWARE ENGINEERING FOR ADAPTIVE AND SELF-MANAGING SYSTEMS (SEAMS), 2016, : 151 - 157
  • [37] Design and Development of Multi-Tenant Web Framework
    Kuppusamy, Sivakumar
    Kaniappan, Vivekanandan
    Thirupathi, Devi
    INTERNATIONAL CONFERENCE ON COMPUTER, COMMUNICATION AND CONVERGENCE (ICCC 2015), 2015, 48 : 180 - 191
  • [38] Using Intrusive Microservices to Enable Deep Customization of Multi-Tenant SaaS
    Chauvel, Franck
    Solberg, Arnor
    2018 11TH INTERNATIONAL CONFERENCE ON THE QUALITY OF INFORMATION AND COMMUNICATIONS TECHNOLOGY (QUATIC), 2018, : 30 - 37
  • [39] Event-Based Customization of Multi-tenant SaaS Using Microservices
    Nordli, Espen Tonnessen
    Nguyen, Phu H.
    Chauvel, Franck
    Song, Hui
    COORDINATION MODELS AND LANGUAGES, COORDINATION 2020, 2020, 12134 : 171 - 180
  • [40] Lightweight Monitoring Scheme for Flooding DoS Attack Detection in Multi-Tenant MPSoCs
    Chaves, Cesar G.
    Sepulveda, Johanna
    Hollstein, Thomas
    2021 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS (ISCAS), 2021,