DocumentCode :
185653
Title :
Security assessment of Eucalyptus´ web management interface
Author :
Donevski, Aleksandar ; Ristov, Sasko ; Gusev, Marjan
Author_Institution :
FCSE, Univ. Ss Cyril & Methodius, Skopje, Macedonia
fYear :
2014
fDate :
26-30 May 2014
Firstpage :
1372
Lastpage :
1375
Abstract :
Three approaches exist for a company to migrate its services in the cloud. The first is select the most appropriate commercial cloud provider, such as Microsoft, Amazon, Google or SalesForce, and to rent their resources and deploy its services. These cloud service providers The second approach is to build a private cloud with some of the open source cloud frameworks like Eucalyptus, OpenStack, OpenNebula or CloudStack. Finally, the third option is to build a hybrid cloud, i.e., to split the services and to migrate the confidential and private services in its own private cloud, which could be open source, while the public and non confidential services and data to migrate in some public commercial cloud. Commercial cloud providers encash for their resources as a service, but offer and guarantee secured resources and huge availability of minimum 99.9% through a SLAs (Service Level Agreements). On the other hand, building an open source private cloud is the lowest starting investment, which does not guarantee neither security nor availability. Therefore, it is important for a company to assess the security of the open source cloud frameworks, especially their web management interface since it is the front end application, through which a user can get an unauthorized access to the company´s data or applications. Eucalyptus is one of the most common open source cloud frameworks for building IaaS (Infrastructure as a Service) private or hybrid clouds, which also has its own web management interface to manage the cloud resources. In this paper, we assess the security of the cloud framework web management interface of the newest version of the Eucalyptus cloud. The results of the security assessment analysis show that the cloud web management interface is vulnerable. We assess the security vulnerabilities and propose measures how to secure them.
Keywords :
Web services; cloud computing; public domain software; telecommunication security; Eucalyptus cloud; IaaS hybrid clouds; SLA; cloud resources; cloud service providers; commercial cloud provider; infrastructure as a service hybrid; investment; nonconfidential services; open source cloud frameworks; open source private cloud; private services; public commercial cloud; security assessment analysis; security vulnerabilities; service level agreements; web management interface; Cloud computing; Companies; Computer architecture; IEEE Computer Society; Security; Servers; Cloud Computing; Dashboard; Open Source; Vulnerability; Web Services!; Web ServicesCloud Computing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information and Communication Technology, Electronics and Microelectronics (MIPRO), 2014 37th International Convention on
Conference_Location :
Opatija
Print_ISBN :
978-953-233-081-6
Type :
conf
DOI :
10.1109/MIPRO.2014.6859781
Filename :
6859781
Link To Document :
بازگشت