• DocumentCode
    74502
  • Title

    Scalable Distributed Service Integrity Attestation for Software-as-a-Service Clouds

  • Author

    Juan Du ; Dean, Daniel J. ; Yongmin Tan ; Xiaohui Gu ; Ting Yu

  • Author_Institution
    Amazon, Seattle, WA, USA
  • Volume
    25
  • Issue
    3
  • fYear
    2014
  • fDate
    Mar-14
  • Firstpage
    730
  • Lastpage
    739
  • Abstract
    Software-as-a-service (SaaS) cloud systems enable application service providers to deliver their applications via massive cloud computing infrastructures. However, due to their sharing nature, SaaS clouds are vulnerable to malicious attacks. In this paper, we present IntTest, a scalable and effective service integrity attestation framework for SaaS clouds. IntTest provides a novel integrated attestation graph analysis scheme that can provide stronger attacker pinpointing power than previous schemes. Moreover, IntTest can automatically enhance result quality by replacing bad results produced by malicious attackers with good results produced by benign service providers. We have implemented a prototype of the IntTest system and tested it on a production cloud computing infrastructure using IBM System S stream processing applications. Our experimental results show that IntTest can achieve higher attacker pinpointing accuracy than existing approaches. IntTest does not require any special hardware or secure kernel support and imposes little performance impact to the application, which makes it practical for large-scale cloud systems.
  • Keywords
    cloud computing; data analysis; security of data; IBM System S; IntTest system; SaaS cloud systems; application service providers; attacker pinpointing accuracy; cloud computing infrastructures; integrated attestation graph analysis scheme; malicious attacks; scalable distributed service; service integrity attestation; software-as-a-service clouds; stream processing applications; Cloud computing; Data processing; Hardware; Portals; Security; Software as a service; Distributed service integrity attestation; cloud computing; secure distributed data processing;
  • fLanguage
    English
  • Journal_Title
    Parallel and Distributed Systems, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1045-9219
  • Type

    jour

  • DOI
    10.1109/TPDS.2013.62
  • Filename
    6471974