• DocumentCode
    3739497
  • Title

    Security Compliance Auditing of Identity and Access Management in the Cloud: Application to OpenStack

  • Author

    Suryadipta Majumdar;Taous Madi;Yushun Wang;Yosr Jarraya;Makan Pourzandi;Lingyu Wang;Mourad Debbabi

  • Author_Institution
    Concordia Inst. for Inf. Syst. Eng., Concordia Univ., Montreal, QC, Canada
  • fYear
    2015
  • Firstpage
    58
  • Lastpage
    65
  • Abstract
    Cloud computing has seen a lot of interests and adoption lately. Nonetheless, the widespread adoption of cloud is still being hindered by the lack of transparency and accountability, which has traditionally been ensured through security compliance auditing techniques. Auditing in cloud, however, presents many new challenges in data collection and processing (e.g., data format inconsistency and lack of correlation due to the heterogeneity of cloud infrastructures) and in verification (e.g., prohibitive performance overhead due to the sheer scale of cloud infrastructures and their self-provisioning, elastic, and dynamic nature). In this paper, we propose a security compliance auditing framework for cloud, with special focus on identity and access management, and we implement and evaluate the framework based on OpenStack, one of the most popular cloud management systems. Our experimental results show that auditing with formal methods in large cloud environment is realistic (e.g., our auditing solution can handle 60 thousand users in less than one minute).
  • Keywords
    "Cloud computing","ISO Standards","Authorization","Computational modeling"
  • Publisher
    ieee
  • Conference_Titel
    Cloud Computing Technology and Science (CloudCom), 2015 IEEE 7th International Conference on
  • Type

    conf

  • DOI
    10.1109/CloudCom.2015.80
  • Filename
    7396138