DocumentCode
2181773
Title
Logging Solutions to Mitigate Risks Associated with Threats in Infrastructure as a Service Cloud
Author
Winai Wongthai ; Rocha, F. ; Van Moorsel, Aad
Author_Institution
Sch. of Comput. Sci., Newcastle Univ., Newcastle upon Tyne, UK
fYear
2013
fDate
16-19 Dec. 2013
Firstpage
163
Lastpage
170
Abstract
Cloud computing offers computational resources such as processing, networking, and storage to customers. However, the cloud also brings with it security concerns which affect both cloud consumers and providers. The Cloud Security Alliance (CSA) define the security concerns as the seven main threats. This paper investigates how threat number one (malicious activities performed in consumers´ virtual machines/VMs) can affect the security of both consumers and providers. It proposes logging solutions to mitigate risks associated with this threat. We systematically design and implement a prototype of the proposed logging solutions in an IaaS to record the history of customer VM´s files. The proposed system can be modified in order to record VMs´ process behaviour log files. These log files can assist in identifying malicious activities (spamming) performed in the VMs as an example of how the proposed solutions benefits the provider side. The proposed system can record the log files while having a smaller trusted computing base compared to previous work. Thus, the logging solutions in this paper can assist in mitigating risks associated with the CSA threats to benefit consumers and providers.
Keywords
cloud computing; operating systems (computers); risk analysis; security of data; virtual machines; CSA; IaaS; cloud computing; cloud consumers; cloud providers; cloud security alliance; computational resources; consumers virtual machines-VM; infrastructure as a service cloud; logging solutions; malicious activities; risks associated; security concerns; Business; Cloud computing; Electronic mail; History; Postal services; Prototypes; Security; accountability; cloud monitoring; logging system;
fLanguage
English
Publisher
ieee
Conference_Titel
Cloud Computing and Big Data (CloudCom-Asia), 2013 International Conference on
Conference_Location
Fuzhou
Print_ISBN
978-1-4799-2829-3
Type
conf
DOI
10.1109/CLOUDCOM-ASIA.2013.70
Filename
6820988
Link To Document