Security policy verification for multi-domains in cloud systems

Gouglidis, Antonios and Mavridis, Ioannis and Hu, Vincent C. (2014) Security policy verification for multi-domains in cloud systems. International Journal of Information Security, 13 (2). pp. 97-111. ISSN 1615-5262

Full text not available from this repository.

Abstract

The cloud is a modern computing paradigm with the ability to support a business model by providing multi-tenancy, scalability, elasticity, pay as you go and self-provisioning of resources by using broad network access. Yet, cloud systems are mostly bounded to single domains, and collaboration among different cloud systems is an active area of research. Over time, such collaboration schemas are becoming of vital importance since they allow companies to diversify their services on multiple cloud systems to increase both uptime and usage of services. The existence of an efficient management process for the enforcement of security policies among the participating cloud systems would facilitate the adoption of multi-domain cloud systems. An important issue in collaborative environments is secure inter-operation. Stemmed from the absence of relevant work in the area of cloud computing, we define a model checking technique that can be used as a management service/tool for the verification of multi-domain cloud policies. Our proposal is based on NIST's (National Institute of Standards and Technology) generic model checking technique and has been enriched with RBAC reasoning. Current approaches, in Grid systems, are capable of verifying and detect only conflicts and redundancies between two policies. However, the latter cannot overcome the risk of privileged user access in multi-domain cloud systems. In this paper, we provide the formal definition of the proposed technique and security properties that have to be verified in multi-domain cloud systems. Furthermore, an evaluation of the technique through a series of performance tests is provided.

Item Type:
Journal Article
Journal or Publication Title:
International Journal of Information Security
Uncontrolled Keywords:
/dk/atira/pure/subjectarea/asjc/1700/1705
Subjects:
?? cloud computingcollaborationmulti-domainrbacsecure inter-operationverificationcomputer networks and communicationssoftwareinformation systemssafety, risk, reliability and quality ??
ID Code:
76366
Deposited By:
Deposited On:
26 Oct 2015 09:42
Refereed?:
Yes
Published?:
Published
Last Modified:
18 Sep 2024 15:30