An Automated Security Analysis Framework and Implementation for Cloud

04/03/2019
by   Hootan Alavizadeh, et al.
0

Cloud service providers offer their customers with on-demand and cost-effective services, scalable computing, and network infrastructures. Enterprises migrate their services to the cloud to utilize the benefit of cloud computing such as eliminating the capital expense of their computing need. There are security vulnerabilities and threats in the cloud. Many researches have been proposed to analyze the cloud security using Graphical Security Models (GSMs) and security metrics. In addition, it has been widely researched in finding appropriate defensive strategies for the security of the cloud. Moving Target Defense (MTD) techniques can utilize the cloud elasticity features to change the attack surface and confuse attackers. Most of the previous work incorporating MTDs into the GSMs are theoretical and the performance was evaluated based on the simulation. In this paper, we realized the previous framework and designed, implemented and tested a cloud security assessment tool in a real cloud platform named UniteCloud. Our security solution can (1) monitor cloud computing in real-time, (2) automate the security modeling and analysis and visualize the GSMs using a Graphical User Interface via a web application, and (3) deploy three MTD techniques including Diversity, Redundancy, and Shuffle on the real cloud infrastructure. We analyzed the automation process using the APIs and showed the practicality and feasibility of automation of deploying all the three MTD techniques on the UniteCloud.

READ FULL TEXT
research
03/11/2019

CloudSafe: A Tool for an Automated Security Analysis for Cloud Computing

Cloud computing has been adopted widely, providing on-demand computing r...
research
09/04/2020

Evaluating the Security and Economic Effects of Moving Target Defense Techniques on the Cloud

Moving Target Defense (MTD) is a proactive security mechanism which chan...
research
09/03/2020

Cyber Situation Awareness Monitoring and Proactive Response for Enterprises on the Cloud

The cloud model allows many enterprises able to outsource computing reso...
research
07/31/2023

AMOE: a Tool to Automatically Extract and Assess Organizational Evidence for Continuous Cloud Audit

The recent spread of cloud services has enabled many companies to take a...
research
12/23/2018

Markov Game Modeling of Moving Target Defense for Strategic Detection of Threats in Cloud Networks

The processing and storage of critical data in large-scale cloud network...
research
02/10/2018

About being the Tortoise or the Hare? - A Position Paper on Making Cloud Applications too Fast and Furious for Attackers

Cloud applications expose - beside service endpoints - also potential or...
research
05/15/2018

Securing Open Source Clouds Using Models

The widespread adoption of cloud computing has resulted in the prolifera...

Please sign up or login with your details

Forgot password? Click here to reset