Cloud Property Graph: Connecting Cloud Security Assessments with Static Code Analysis

06/14/2022
by   Christian Banse, et al.
0

In this paper, we present the Cloud Property Graph (CloudPG), which bridges the gap between static code analysis and runtime security assessment of cloud services. The CloudPG is able to resolve data flows between cloud applications deployed on different resources, and contextualizes the graph with runtime information, such as encryption settings. To provide a vendor- and technology-independent representation of a cloud service's security posture, the graph is based on an ontology of cloud resources, their functionalities and security features. We show, using an example, that our CloudPG framework can be used by security experts to identify weaknesses in their cloud deployments, spanning multiple vendors or technologies, such as AWS, Azure and Kubernetes. This includes misconfigurations, such as publicly accessible storages or undesired data flows within a cloud service, as restricted by regulations such as GDPR.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/09/2019

A Security Framework for Cloud Data Storage(CDS) Based on Agent

The Cloud has become a new Information Technology(IT) model for deliveri...
research
07/29/2018

Virtualization Technologies and Cloud Security: advantages, issues, and perspectives

Virtualization technologies allow multiple tenants to share physical res...
research
08/27/2019

Analysis of SLA Compliance in the Cloud – An Automated, Model-based Approach

Service Level Agreements (SLA) are commonly used to specify the quality ...
research
05/09/2022

Static Analysis for AWS Best Practices in Python Code

Amazon Web Services (AWS) is a comprehensive and broadly adopted cloud p...
research
08/14/2023

Towards a Cloud-Based Ontology for Service Model Security – Technical Report

The adoption of cloud computing has brought significant advancements in ...
research
09/03/2020

Cyber Situation Awareness Monitoring and Proactive Response for Enterprises on the Cloud

The cloud model allows many enterprises able to outsource computing reso...
research
04/21/2023

Outsourced Analysis of Encrypted Graphs in the Cloud with Privacy Protection

Huge diagrams have unique properties for organizations and research, suc...

Please sign up or login with your details

Forgot password? Click here to reset