SNUAGE: an efficient platform-as-a-service security framework for the cloud

被引:0
|
作者
Wassim Itani
Ayman Kayssi
Ali Chehab
机构
[1] Beirut Arab University,Department of Electrical and Computer Engineering
[2] American University of Beirut,Department of Electrical and Computer Engineering
来源
Cluster Computing | 2013年 / 16卷
关键词
Cloud computing security; Platform-as-a-Service security; Data confidentiality; Integrity; Policy-based security;
D O I
暂无
中图分类号
学科分类号
摘要
In this paper we present SNUAGE, a platform-as-a-service security framework for building secure and scalable multi-layered services based on the cloud computing model. SNUAGE ensures the authenticity, integrity, and confidentiality of data communication over the network links by creating a set of security associations between the data-bound components on the presentation layer and their respective data sources on the data persistence layer. SNUAGE encapsulates the security procedures, policies, and mechanisms in these security associations at the service development stage to form a collection of isolated and protected security domains. The secure communication among the entities in one security domain is governed and controlled by a standalone security processor and policy attached to this domain. This results into: (1) a safer data delivery mechanism that prevents security vulnerabilities in one domain from spreading to the other domains and controls the inter-domain information flow to protect the privacy of network data, (2) a reusable security framework that can be employed in existing platform-as-a-service environments and across diverse cloud computing service models, and (3) an increase in productivity and delivery of reliable and secure cloud computing services supported by a transparent programming model that relieves application developers from the intricate details of security programming. Last but not least, SNUAGE contributes to a major enhancement in the energy consumption and performance of supported cloud services by providing a suitable execution container in its protected security domains for a wide suite of energy- and performance-efficient cryptographic constructs such as those adopted by policy-driven and content-based security protocols. An energy analysis of the system shows, via real energy measurements, major savings in energy consumption on the consumer devices as well as on the cloud servers. Moreover, a sample implementation of the presented security framework is developed using Java and deployed and tested in a real cloud computing infrastructure using the Google App Engine service platform. Performance benchmarks show that the proposed framework provides a significant throughput enhancement compared to traditional network security protocols such as the Secure Sockets Layer and the Transport Layer Security protocols.
引用
收藏
页码:707 / 724
页数:17
相关论文
共 50 条
  • [41] Holistic Framework of Security Management for Cloud Service Providers
    Zhao, Gang
    2012 10TH IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL INFORMATICS (INDIN), 2012, : 852 - 856
  • [42] Combined and Improved Framework of Infrastructure as a Service and Platform as a Service in Cloud Computing
    Rana, Poonam
    Gupta, P. K.
    Siddavatam, Rajesh
    PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON SOFT COMPUTING FOR PROBLEM SOLVING (SOCPROS 2012), 2014, 236 : 831 - 839
  • [43] Test as a Service: A framework for Web security TaaS service in cloud environment
    Tung, Yuan-Hsin
    Lin, Chen-Chiu
    Shan, Hwai-Ling
    2014 IEEE 8TH INTERNATIONAL SYMPOSIUM ON SERVICE ORIENTED SYSTEM ENGINEERING (SOSE), 2014, : 212 - 217
  • [44] Security Research on Cloud-Based Logistics Service Platform
    Sun, Fuquan
    Liu, Chao
    Cheng, Xu
    Zhang, Dawei
    INTERNET OF THINGS-BK, 2012, 312 : 394 - 400
  • [45] A Review of Research on Security of Cloud Service Platform in Medical Environment
    Liu, Kun
    Chen, Chunling
    Guo, Jianjun
    Li, Qi
    Guo, Yongan
    2019 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS - TAIWAN (ICCE-TW), 2019,
  • [46] Architectting the Recommendation Layer of a Platform-as-a-Service e-Marketplace
    AhmadiZeleti, Fatemeh
    Hassan, Islam
    Abbas, Sonya
    Ojo, Adegboyega
    Porwol, Lukasz
    ICSOFT-EA: PROCEEDINGS OF THE 11TH INTERNATIONAL JOINT CONFERENCE ON SOFTWARE TECHNOLOGIES - VOL. 1, 2016, : 336 - 341
  • [47] Kameleo: Design of a new Platform-as-a-Service for Flexible Data Management
    Vanhove, Thomas
    Vandensteen, Jeroen
    Van Seghbroeck, Gregory
    Wauters, Tim
    De Turck, Filip
    2014 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (NOMS), 2014,
  • [48] Architecture of a Marine Information Service Platform: A Cloud Computing Framework
    Han, Qi
    JOURNAL OF COASTAL RESEARCH, 2020, : 596 - 599
  • [49] A Security Assessment Framework and Selection Method for Outsourcing Cloud Service
    Liu, Xiaochen
    Xia, Chunhe
    Cao, Jiajin
    Gao, Jinghua
    Wei, Zhao
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2014, 8 (06): : 375 - 388
  • [50] Mutual Auditing Framework for Service Level Security Auditing in Cloud
    Sasmal, Soumitra
    Pan, Indrajit
    2017 THIRD IEEE INTERNATIONAL CONFERENCE ON RESEARCH IN COMPUTATIONAL INTELLIGENCE AND COMMUNICATION NETWORKS (ICRCICN), 2017, : 297 - 302