Enhancing cloud security with context-aware usage control policies
Zusammenfassung
Cloud environments strongly rely on virtualization infrastructure that provides virtual resources by abstracting from the physical hardware. Thus, cloud providers can cost-efficiently share physical hardware among multiple tenants, and a single virtual resource may span multiple physical resources at different geo-locations. From a tenant's perspective, the uncertainty about location and context of virtual resources is a potential security threat. For instance, tenants may want to enforce geo-fencing to prevent their applications and data from migrating to undesirable jurisdictions, untrusted co-tenants, or dubious locations. They may also want to ensure that certain virtual resources share (or expressly do not share) a common physical resource, for example, to improve fault tolerance or performance. To tackle these problems, we suggest a flexible policy decision and enforcement framework for enabling usage control in cloud environments. In support of this framework, we collect additional information from the cloud environment to enforce context-aware and therefore more fine-grained usage control policies. Our solution offers flexible controls for secure and resilient cloud management. The paper presents our policy enforcement framework IND2UCE and its extension to enable context-ware policy enforcement on an exemplary cloud infrastructure using VMware products.
- Vollständige Referenz
- BibTeX
Jung, C., Eitel, A. & Schwarz, R.,
(2014).
Enhancing cloud security with context-aware usage control policies.
In:
Plödereder, E., Grunske, L., Schneider, E. & Ull, D.
(Hrsg.),
Informatik 2014.
Bonn:
Gesellschaft für Informatik e.V..
(S. 211-222).
@inproceedings{mci/Jung2014,
author = {Jung, Christian AND Eitel, Andreas AND Schwarz, Reinhard},
title = {Enhancing cloud security with context-aware usage control policies},
booktitle = {Informatik 2014},
year = {2014},
editor = {Plödereder, E. AND Grunske, L. AND Schneider, E. AND Ull, D.} ,
pages = { 211-222 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
author = {Jung, Christian AND Eitel, Andreas AND Schwarz, Reinhard},
title = {Enhancing cloud security with context-aware usage control policies},
booktitle = {Informatik 2014},
year = {2014},
editor = {Plödereder, E. AND Grunske, L. AND Schneider, E. AND Ull, D.} ,
pages = { 211-222 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken
Mehr Information
ISBN: 978-3-88579-626-8
ISSN: 1617-5468
Datum: 2014
Sprache:
(en)
(en)
Typ: Text/Conference Paper
Sammlungen
- P232 - INFORMATIK 2014 [297]

