Architectures for Protecting Cloud Data Planes

01/31/2022
by   Grant Dasher, et al.
0

This paper explores three approaches for protecting cloud application data planes to prevent unauthorized access to the application and its data and to prevent unwanted data exfiltration. Through an exploration of various concrete security architectures, we focus on (1) Cloud Security Perimeters to provide a boundary around data and infrastructure in the cloud that provides a line of defense both to improper access to sensitive information and the exfiltration of that information, (2) Cloud Landing Points to provide a safe integration point between parts of your cloud applications and on-premises applications to communicate through, and (3) Zero Trust security architectures that are built on the principles of defense in depth and least-privilege access. Using these approaches together provides critical protection for services and applications as they transition from traditional on-premises network security to the Cloud security architectures, and then to potentially Zero Trust security architectures.

READ FULL TEXT

page 10

page 18

page 21

page 22

page 24

page 29

page 32

page 34

research
07/13/2019

A Secure Cloud with Minimal Provider Trust

Bolted is a new architecture for a bare metal cloud with the goal of pro...
research
05/04/2021

Intelligent Zero Trust Architecture for 5G/6G Tactical Networks: Principles, Challenges, and the Role of Machine Learning

In this position paper, we discuss the critical need for integrating zer...
research
01/16/2019

Secure Cloud-Edge Deployments, with Trust

Assessing the security level of IoT applications to be deployed to heter...
research
03/15/2022

Zero Trust Architecture for 6G Security

The upcoming sixth generation (6G) network is envisioned to be more open...
research
03/06/2023

Scenario-Agnostic Zero-Trust Defense with Explainable Threshold Policy: A Meta-Learning Approach

The increasing connectivity and intricate remote access environment have...
research
07/13/2019

Supporting Security Sensitive Tenants in a Bare-Metal Cloud

Bolted is a new architecture for bare-metal clouds that enables tenants ...
research
04/24/2020

6G White paper: Research challenges for Trust, Security and Privacy

The roles of trust, security and privacy are somewhat interconnected, bu...

Please sign up or login with your details

Forgot password? Click here to reset