Skip to main content
QUICK REVIEW

[论文解读] An Efficient Framework for Information Security in Cloud Computing Using Auditing Algorithm Shell (AAS)

Maria Mushtaq, Furrakh Shahzad|arXiv (Cornell University)|Feb 23, 2017
Cloud Data Security Solutions参考文献 10被引用 10
一句话总结

本文提出了一种四层审计框架——审计算法壳(AAS),通过整合安全数据传输、加密数据处理、数据库安全壳以及内部/外部日志审计,提升云计算中的信息安全。该框架通过分层安全机制增强信任与数据机密性,在减轻数据泄露风险和确保合规性方面表现出有效性。

ABSTRACT

There is a dynamic escalation and extension in the new infrastructure, educating personnel and licensing new computer programs in the field of IT, due to the emergence of Cloud Computing (CC) paradigm. It has become a quick growing segment of IT business in last couple of years. However, due to the rapid growth of data, people and IT firms, the issue of information security is getting more complex. One of the major concerns of the user is, at what degree the data is safe on Cloud? In spite of all promotional material encompassing the cloud, consortium customers are not willing to shift their business on the cloud. Data security is the major problem which has limited the scope of cloud computing. In new cloud computing infrastructure, the techniques such as the Strong Secure Shell and Encryption are deployed to guarantee the authenticity of the user through logs systems. The vendors utilize these logs to analyze and view their data. Therefore, this implementation is not enough to ensure security, privacy and authoritative use of the data. This paper introduces quad layered framework for data security, data privacy, data breaches and process associated aspects. Using this layered architecture we have preserved the secrecy of confidential information and tried to build the trust of user on cloud computing. This layered framework prevents the confidential information by multiple means i.e. Secure Transmission of Data, Encrypted Data and its Processing, Database Secure Shell and Internal/external log Auditing.

研究动机与目标

  • 为应对由于数据量增加和用户不信任而日益加剧的云计算中数据安全与隐私问题。
  • 克服现有认证与日志机制在确保端到端数据保护方面的局限性。
  • 开发一个全面的、分层的安全框架,确保云环境中数据的机密性、完整性和可审计性。
  • 通过可验证的审计和安全的数据处理,增强用户对云服务提供商的信任。
  • 将多种安全控制措施——加密、安全传输、安全壳和日志审计——整合到统一框架中。

提出的方法

  • 该框架采用四层架构:安全数据传输、加密数据处理、数据库安全壳(DB-SSH)以及内部/外部日志审计。
  • 通过密码学协议强制实施安全传输,以保护传输中的数据。
  • 在存储和处理前对数据进行加密,使用强加密算法以保持机密性。
  • 实现数据库安全壳(DB-SSH)以控制和审计数据库访问,确保仅授权操作可执行。
  • 采用内部和外部日志审计机制监控和验证系统活动,提升透明度与问责性。
  • 审计算法壳(AAS)协调这些层次,支持实时监控和异常的自动检测。

实验结果

研究问题

  • RQ1分层安全框架在多大程度上能提升云计算环境中的数据机密性和完整性?
  • RQ2集成的审计与加密机制在多大程度上能降低云存储中的数据泄露风险?
  • RQ3统一的审计壳能否增强云用户与服务提供商之间的信任?
  • RQ4安全传输、加密处理与日志审计的组合在检测未授权访问方面有多有效?
  • RQ5DB-SSH在保护云环境中数据库操作方面发挥什么作用?

主要发现

  • 所提出的AAS框架通过整合加密、安全传输和审计等多种保护层次,显著提升了数据安全性。
  • 该框架通过可验证的审计和透明的日志管理增强了用户信任,降低了对数据滥用的担忧。
  • DB-SSH与日志审计的集成实现了对未授权数据库访问尝试的实时监控与检测。
  • 分层方法确保了端到端的安全性,最大限度减少了数据处理与工作流中的漏洞。
  • 该框架在减轻常见云安全威胁(如数据泄露和内部攻击)方面具有可行性。
  • 研究证实,将加密、安全传输与审计机制相结合,可构建更加稳健和可信的云环境。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。