Security Attack Mitigation Framework for the Cloud

被引:0
|
作者
Datta, Esha [1 ]
Goyal, Neeraj [1 ]
机构
[1] Indian Inst Technol Kharagpur, Ctr Reliabil Engn, Kharagpur 721302, W Bengal, India
关键词
Cloud computing; Security; Attack Graphs; Markov Chain; Security Administration;
D O I
暂无
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Cloud computing brings in a lot of advantages for enterprise IT infrastructure; virtualization technology, which is the backbone of cloud, provides easy consolidation of resources, reduction of cost, space and management efforts. However, security of critical and private data is a major concern which still keeps back a lot of customers from switching over from their traditional in-house IT infrastructure to a cloud service. Existence of techniques to physically locate a virtual machine in the cloud, proliferation of software vulnerability exploits and cross-channel attacks in-between virtual machines, all of these together increases the risk of business data leaks and privacy losses. This work proposes a framework to mitigate such risks and engineer customer trust towards enterprise cloud computing. Everyday new vulnerabilities are being discovered even in well-engineered software products and the hacking techniques are getting sophisticated over time. In this scenario, absolute guarantee of security in enterprise wide information processing system seems a remote possibility; software systems in the cloud are vulnerable to security attacks. Practical solution for the security problems lies in well-engineered attack mitigation plan. At the positive side, cloud computing has a collective infrastructure which can be effectively used to mitigate the attacks if an appropriate defense framework is in place. We propose such an attack mitigation framework for the cloud. Software vulnerabilities in the cloud have different severities and different impacts on the security parameters (confidentiality, integrity, and availability). By using Markov model, we continuously monitor and quantify the risk of compromise in different security parameters (e. g.: change in the potential to compromise the data confidentiality). Whenever, there is a significant change in risk, our framework would facilitate the tenants to calculate the Mean Time to Security Failure (MTTSF) cloud and allow them to adopt a dynamic mitigation plan. This framework is an add-on security layer in the cloud resource manager and it could improve the customer trust on enterprise cloud solutions.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] A Vulnerability based Attack Detection and Mitigation in Cloud SaaS Framework
    Saisindhutheja R.
    Shyam G.K.
    Makka S.
    [J]. Journal of Engineering Science and Technology Review, 2022, 15 (05) : 158 - 169
  • [2] Attack Mitigation and Security for Vehicle Platoon
    Ndambuki D.K.
    Alhitmi H.K.
    [J]. Journal of Cyber Security and Mobility, 2022, 11 (04): : 497 - 530
  • [3] Cloud Security Automation Framework
    Tunc, Cihan
    Hariri, Salim
    Merzouki, Mheni
    Mahmoudi, Charif
    de Vaulx, Frederic J.
    Chbili, Jaafar
    Bohn, Robert
    Battou, Abdella
    [J]. 2017 IEEE 2ND INTERNATIONAL WORKSHOPS ON FOUNDATIONS AND APPLICATIONS OF SELF* SYSTEMS (FAS*W), 2017, : 307 - 312
  • [4] A Framework for Cloud Security Audit
    Ismail, Umar Mukhtar
    Islam, Shareeful
    Mouratidis, Haralambus
    [J]. GLOBAL SECURITY, SAFETY AND SUSTAINABILITY: TOMORROW'S CHALLENGES OF CYBER SECURITY, ICGS3 2015, 2015, 534 : 296 - 309
  • [5] Toward a Framework for Cloud Security
    Brock, Michael
    Goscinski, Andrzej
    [J]. ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, PT 2, PROCEEDINGS, 2010, 6082 : 254 - 263
  • [6] A Framework for Cloud Data Security
    Grover, Ankit
    Kaur, Banpreet
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND AUTOMATION (ICCCA), 2016, : 1199 - 1203
  • [7] A SECURITY METRICS FRAMEWORK FOR THE CLOUD
    Luna, Jesus
    Ghani, Hamza
    Gemianus, Daniel
    Suni, Neeraj
    [J]. SECRYPT 2011: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2011, : 245 - 250
  • [8] A SECURITY FRAMEWORK FOR CLOUD MANUFACTURING
    Wang, Yazhe
    Ma, Shunan
    Ren, Lei
    [J]. PROCEEDINGS OF THE ASME 9TH INTERNATIONAL MANUFACTURING SCIENCE AND ENGINEERING CONFERENCE, 2014, VOL 1, 2014,
  • [9] A DDoS Attack Mitigation Framework for Internet of Things
    Adat, Vipindev
    Gupta, B. B.
    [J]. 2017 INTERNATIONAL CONFERENCE ON COMMUNICATION AND SIGNAL PROCESSING (ICCSP), 2017, : 2036 - 2041
  • [10] A security evaluation framework for cloud security auditing
    Rizvi, Syed
    Ryoo, Jungwoo
    Kissell, John
    Aiken, William
    Liu, Yuhong
    [J]. JOURNAL OF SUPERCOMPUTING, 2018, 74 (11): : 5774 - 5796