• DocumentCode
    182162
  • Title

    Secgras: Security Group Analysis as a Cloud Service

  • Author

    Cheng Jin ; Srivastava, Anurag ; Yu Jin ; Zhi-Li Zhang

  • fYear
    2014
  • fDate
    21-24 Oct. 2014
  • Firstpage
    215
  • Lastpage
    220
  • Abstract
    To ensure security, cloud service providers employ security groups as a key tool for cloud tenants to protect their virtual machines from unwanted traffic. However, security groups can be complex and often hard to configure, which may result in security vulnerabilities that impact the entire cloud platform. To assist tenants in designing better security groups, in this paper, we propose and develop a system called Secgras. Secgras enables tenants to visualize and hence to understand the static and dynamic access relations among virtual machine (VM) instances. Secgras also helps diagnose potential misconfigurations and provides suggestions to refine security group configurations based on real traffic traversing tenants VMs.
  • Keywords
    cloud computing; security of data; Secgras; VM; cloud tenants; real traffic; security group analysis as a cloud service; virtual machines; Cloud computing; IP networks; Periodic structures; Ports (Computers); Protocols; Security; Visualization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Protocols (ICNP), 2014 IEEE 22nd International Conference on
  • Conference_Location
    Raleigh, NC
  • Print_ISBN
    978-1-4799-6203-7
  • Type

    conf

  • DOI
    10.1109/ICNP.2014.42
  • Filename
    6980381