论文标题

网络状况意识监测和对云上企业的积极反应

Cyber Situation Awareness Monitoring and Proactive Response for Enterprises on the Cloud

论文作者

Alavizadeh, Hootan, Alavizadeh, Hooman, Jang-Jaccard, Julian

论文摘要

云模型允许许多企业能够以负担得起的价格外包计算资源,而无需提前支出费用。尽管云提供商负责云的安全性,但由于固有的复杂模型,云提供商在运行(例如,多租赁)仍然存在许多安全问题。此外,服务已迁移到云中的企业还偏爱自己的网络安全状况意识能力,除了云提供商提供的安全机制之外。通过这种方式,企业可以监视云的安全产品的性能,并可以选择在存在云提供的防御范围不适合其的情况下,在存在攻击的情况下决定和选择对企业更适合企业的潜在响应策略。但是,企业本身不能部署一些响应策略,例如显示为保护云具有有效云的迁移目标防御(MTD)技术。在本文中,我们提出了一个框架,该框架可以使企业和云提供商之间更好地合作。我们提出的框架基于最先进的安全指标提供了更多深入的安全分析,使企业的安全专家能够在云中获得更好的情境意识。凭借对云安全性的更好,更有效的情况,我们的框架可以支持更好的决策制定,并进一步部署更适当的威胁响应以保护外包资源。我们还提出了一个安全的协议,该协议可以促进企业和云提供商之间更安全的通信。使用我们提出的安全协议,该协议基于身份验证和密钥交换机制,企业可以向云提供商发送安全请求以执行所选的防御策略。

The cloud model allows many enterprises able to outsource computing resources at an affordable price without having to commit the expense upfront. Although the cloud providers are responsible for the security of the cloud, there are still many security concerns due to inherently complex model the cloud providers operate on (e.g.,multi-tenancy). In addition, the enterprises whose services have migrated into the cloud have a preference for their own cybersecurity situation awareness capability on top of the security mechanisms provided by the cloud providers. In this way, the enterprises can monitor the performance of the security offerings of the cloud and have a choice to decide and select potential response strategies more appropriate to the enterprise in the presence of the attack where the defense provided by the cloud doesn't work for them. However, some response strategies, such as Moving Target Defense (MTD) techniques shown to be effective to secure cloud, cannot be deployed by the enterprise themselves. In this paper, we propose a framework that enables better collaboration between enterprises and cloud providers. Our proposed framework, which offers more in-depth security analysis based on the set of most advanced security metrics, allows the security experts of the enterprise to obtain better situational awareness in the cloud. With better and more effective situation awareness of cloud security, our framework can support better decision making and further allows to deploy more appropriate threat responses to protect the outsourced resources. We also propose a secure protocol which can facilitate more secure communication between the enterprises and cloud provider. Using our proposed secure protocol, which is based on authentication and key exchange mechanism, the enterprises can send a secure request to the cloud provider to perform a selected defensive strategy.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源