• DocumentCode
    614120
  • Title

    A Generic Logging Template for Infrastructure as a Service Cloud

  • Author

    Wongthai, W. ; Rocha, F.L. ; Van Moorsel, Aad

  • Author_Institution
    Sch. of Comput. Sci., Newcastle Univ., Newcastle uopn Tyne, UK
  • fYear
    2013
  • fDate
    25-28 March 2013
  • Firstpage
    1153
  • Lastpage
    1160
  • Abstract
    Infrastructure as a Service (IaaS) consists of a cloud-based infrastructure to offer consumers raw computation resources such as storage and networking. These resources are billed using a pay-per-use cost model. However, this type of infrastructure is far from being a security haven as the seven main threats defined by the Cloud Security Alliance (CSA) indicate. Using logging systems can provide evidence to support accountability for an IaaS cloud, which helps us mitigating known threats. In this paper, we research to which extent such logging systems help mitigate risks associated with the threats identified by the CSA. A generic architecture ´template´ for logging systems is proposed. This template encompasses all possible instantiations of logging solutions for IaaS cloud. We map existing logging systems to our generic template, and identify a logging solution to mitigate the risks associated with CSA threat number one (related to spam activities). We then argue that the template we suggest can be used to perform a systematic analysis of logging systems in terms of security before deploying them in production systems.
  • Keywords
    cloud computing; computerised monitoring; resource allocation; risk analysis; security of data; service-oriented architecture; CSA threat number; IaaS cloud; cloud security alliance; cloud-based infrastructure; generic architecture template; generic logging template; infrastructure as a service cloud; logging systems; pay-per-use cost model; production systems; raw computation resources; risk association; threat identification; threat mitigation; Cloud computing; Computer architecture; Electronic mail; Kernel; Monitoring; Security; Virtual machine monitors; IaaS; cloud monitoring; logging system;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications Workshops (WAINA), 2013 27th International Conference on
  • Conference_Location
    Barcelona
  • Print_ISBN
    978-1-4673-6239-9
  • Electronic_ISBN
    978-0-7695-4952-1
  • Type

    conf

  • DOI
    10.1109/WAINA.2013.108
  • Filename
    6550551