DocumentCode
3739497
Title
Security Compliance Auditing of Identity and Access Management in the Cloud: Application to OpenStack
Author
Suryadipta Majumdar;Taous Madi;Yushun Wang;Yosr Jarraya;Makan Pourzandi;Lingyu Wang;Mourad Debbabi
Author_Institution
Concordia Inst. for Inf. Syst. Eng., Concordia Univ., Montreal, QC, Canada
fYear
2015
Firstpage
58
Lastpage
65
Abstract
Cloud computing has seen a lot of interests and adoption lately. Nonetheless, the widespread adoption of cloud is still being hindered by the lack of transparency and accountability, which has traditionally been ensured through security compliance auditing techniques. Auditing in cloud, however, presents many new challenges in data collection and processing (e.g., data format inconsistency and lack of correlation due to the heterogeneity of cloud infrastructures) and in verification (e.g., prohibitive performance overhead due to the sheer scale of cloud infrastructures and their self-provisioning, elastic, and dynamic nature). In this paper, we propose a security compliance auditing framework for cloud, with special focus on identity and access management, and we implement and evaluate the framework based on OpenStack, one of the most popular cloud management systems. Our experimental results show that auditing with formal methods in large cloud environment is realistic (e.g., our auditing solution can handle 60 thousand users in less than one minute).
Keywords
"Cloud computing","ISO Standards","Authorization","Computational modeling"
Publisher
ieee
Conference_Titel
Cloud Computing Technology and Science (CloudCom), 2015 IEEE 7th International Conference on
Type
conf
DOI
10.1109/CloudCom.2015.80
Filename
7396138
Link To Document