SNUAGE: an efficient platform-as-a-service security framework for the cloud

被引:0
|
作者
Wassim Itani
Ayman Kayssi
Ali Chehab
机构
[1] Beirut Arab University,Department of Electrical and Computer Engineering
[2] American University of Beirut,Department of Electrical and Computer Engineering
来源
Cluster Computing | 2013年 / 16卷
关键词
Cloud computing security; Platform-as-a-Service security; Data confidentiality; Integrity; Policy-based security;
D O I
暂无
中图分类号
学科分类号
摘要
In this paper we present SNUAGE, a platform-as-a-service security framework for building secure and scalable multi-layered services based on the cloud computing model. SNUAGE ensures the authenticity, integrity, and confidentiality of data communication over the network links by creating a set of security associations between the data-bound components on the presentation layer and their respective data sources on the data persistence layer. SNUAGE encapsulates the security procedures, policies, and mechanisms in these security associations at the service development stage to form a collection of isolated and protected security domains. The secure communication among the entities in one security domain is governed and controlled by a standalone security processor and policy attached to this domain. This results into: (1) a safer data delivery mechanism that prevents security vulnerabilities in one domain from spreading to the other domains and controls the inter-domain information flow to protect the privacy of network data, (2) a reusable security framework that can be employed in existing platform-as-a-service environments and across diverse cloud computing service models, and (3) an increase in productivity and delivery of reliable and secure cloud computing services supported by a transparent programming model that relieves application developers from the intricate details of security programming. Last but not least, SNUAGE contributes to a major enhancement in the energy consumption and performance of supported cloud services by providing a suitable execution container in its protected security domains for a wide suite of energy- and performance-efficient cryptographic constructs such as those adopted by policy-driven and content-based security protocols. An energy analysis of the system shows, via real energy measurements, major savings in energy consumption on the consumer devices as well as on the cloud servers. Moreover, a sample implementation of the presented security framework is developed using Java and deployed and tested in a real cloud computing infrastructure using the Google App Engine service platform. Performance benchmarks show that the proposed framework provides a significant throughput enhancement compared to traditional network security protocols such as the Secure Sockets Layer and the Transport Layer Security protocols.
引用
收藏
页码:707 / 724
页数:17
相关论文
共 50 条
  • [1] SNUAGE: an efficient platform-as-a-service security framework for the cloud
    Itani, Wassim
    Kayssi, Ayman
    Chehab, Ali
    [J]. CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2013, 16 (04): : 707 - 724
  • [2] Energy-Efficient Platform-as-a-Service Security Provisioning in the Cloud
    Itani, Wassim
    Chehab, Ali
    Kayssi, Ayman
    [J]. 2011 INTERNATIONAL CONFERENCE ON ENERGY AWARE COMPUTING, 2011,
  • [3] Evaluating Security Mechanisms Implemented on Public Platform-as-a-Service Cloud Environments
    Akinbi, A.
    Pereira, E.
    Beaumont, C.
    [J]. 2013 8TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2013, : 162 - 167
  • [4] CoMoT - A Platform-as-a-Service for Elasticity in the Cloud
    Truong, Hong-Linh
    Dustdar, Schahram
    Copil, Georgiana
    Gambi, Alessio
    Hummer, Waldemar
    Le, Duc-Hung
    Moldovan, Daniel
    [J]. 2014 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E), 2014, : 619 - 622
  • [5] A Cloud Platform-as-a-Service for Multimedia Conferencing Service Provisioning
    Alam, Ahmad F. B.
    Soltanian, Abbas
    Yangui, Sami
    Salahuddin, Mohammad A.
    Glitho, Roch
    Elbiaze, Halima
    [J]. 2016 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATION (ISCC), 2016, : 289 - 294
  • [6] PaaS Manager: A Platform-as-a-Service Aggregation Framework
    Cunha, David
    Neves, Pedro
    Sousa, Pedro
    [J]. COMPUTER SCIENCE AND INFORMATION SYSTEMS, 2014, 11 (04) : 1209 - 1228
  • [7] High Performance Computing Cloud - a Platform-as-a-Service Perspective
    Dhuldhule, Pratima
    Lakshmi, J.
    Nandy, S. K.
    [J]. 2015 INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND BIG DATA (CCBD), 2015, : 21 - 28
  • [8] Design and Analytical Model of a Platform-as-a-Service Cloud for Healthcare
    Hayes, Garrett
    Khazaei, Hamzeh
    El-Khatib, Khalil
    McGregor, Carolyn
    Eklund, J. Milcael
    [J]. JOURNAL OF INTERNET TECHNOLOGY, 2015, 16 (01): : 139 - 149
  • [9] Multi-Cloud Platform-as-a-Service Model, Functionalities and Approaches
    Juan Ferrer, Ana
    Garcia Perez, David
    Sosa Gonzalez, Roman
    [J]. 2ND INTERNATIONAL CONFERENCE ON CLOUD FORWARD: FROM DISTRIBUTED TO COMPLETE COMPUTING, 2016, 97 : 63 - 72
  • [10] Dynalize: Dynamic Analysis of Mobile Apps in a Platform-as-a-Service Cloud
    Graubner, Pablo
    Baumgaertner, Lars
    Heckmann, Patrick
    Mueller, Marcel
    Freisleben, Bernd
    [J]. 2015 IEEE 8TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING, 2015, : 925 - 932