Skip to main content
QUICK REVIEW

[论文解读] A Survey on Cloud Security Issues and Techniques

Shubhanjali Sharma, Garima Gupta|arXiv (Cornell University)|Mar 22, 2014
Cloud Data Security Solutions参考文献 2被引用 4
一句话总结

本综述对云安全挑战(如多租户、数据完整性及访问控制)进行了全面分析,同时探讨了现有的密码学与访问控制技术。它评估了安全模型、工具与框架,以增强云环境中的信任与弹性,为研究人员和从业者提供了截至2014年的威胁与缓解策略的结构化概览。

ABSTRACT

Today, cloud computing is an emerging way of computing in computer science. Cloud computing is a set of resources and services that are offered by the network or internet. Cloud computing extends various computing techniques like grid computing, distributed computing. Today cloud computing is used in both industrial field and academic field. Cloud facilitates its users by providing virtual resources via internet. As the field of cloud computing is spreading the new techniques are developing. This increase in cloud computing environment also increases security challenges for cloud developers. Users of cloud save their data in the cloud hence the lack of security in cloud can lose the users trust. In this paper we will discuss some of the cloud security issues in various aspects like multi-tenancy, elasticity, availability etc. The paper also discuss existing security techniques and approaches for a secure cloud. This paper will enable researchers and professionals to know about different security threats and models and tools proposed.

研究动机与目标

  • 识别并分类基础设施、数据和访问控制层的主要云安全威胁。
  • 分析现有安全技术,包括加密、访问控制模型及入侵检测机制。
  • 评估现有工具与框架在缓解云特定漏洞方面的有效性。
  • 为研究人员和从业者提供关于云计算中不断演进的安全模型与最佳实践的参考。

提出的方法

  • 对多租户、弹性、可用性及数据隐私等云安全问题进行系统性回顾。
  • 将安全威胁分类为数据泄露、内部人员攻击及拒绝服务等类别。
  • 调查对数据机密性保障的对称与非对称加密等密码学技术。
  • 检查RBAC与ABAC等访问控制模型在实施细粒度访问策略方面的作用。
  • 分析专为云环境设计的入侵检测与监控系统。
  • 评估现有云安全工具与框架,包括其可扩展性与部署模式。

实验结果

研究问题

  • RQ1云计算环境中主要的安全挑战是什么,特别是与数据机密性和多租户相关的挑战?
  • RQ2现有密码学与访问控制技术如何缓解云特定威胁?
  • RQ3当前云安全框架在处理动态与分布式工作负载方面存在哪些局限性?
  • RQ4新兴安全模型如何提升公共云与私有云部署中的信任与完整性?
  • RQ5在检测与预防云环境攻击方面,哪些工具与技术最为有效?

主要发现

  • 由于资源隔离失败,多租户机制引入了重大风险,可能导致租户间数据泄露。
  • AES与RSA等加密技术被广泛采用,但需谨慎管理密钥以保持其有效性。
  • 基于角色的访问控制(RBAC)与基于属性的访问控制(ABAC)模型有助于在共享环境中实施细粒度访问策略。
  • 专为云平台设计的入侵检测系统(IDS)可提升早期威胁检测能力,但面临可扩展性挑战。
  • 云服务提供商之间缺乏标准化安全框架,降低了互操作性并扩大了攻击面。
  • 现有工具虽具潜力,但通常缺乏与原生云编排及监控系统的集成。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。