Skip to main content
QUICK REVIEW

[论文解读] Increasing Security in Cloud Environment

Priyanka Naik, Sugata Sanyal|arXiv (Cornell University)|Jan 2, 2013
Cloud Data Security Solutions参考文献 26被引用 4
一句话总结

本文提出了一种多层安全框架,用于云环境,结合加密、访问控制和入侵检测,以增强数据的机密性、完整性和可用性。它评估了孤立和组合安全措施的有效性,表明集成方法能显著降低对常见云威胁(如数据泄露和未授权访问)的脆弱性。

ABSTRACT

The concept of cloud computing was introduced to meet the increase in demand for new application for a project, and to provide a large storage facility whenever or wherever a user needs it. The cloud system facility helped many industries as well as individual users to get authentic software at a very low cost. But with this new system comes the major concern of security, as the connection to the cloud is through the web and the data and application availability need to be handled for each client. The paper describes the various security measures that can be added in isolation or in combination for securing data transmission, server and client.

研究动机与目标

  • 解决由于数据敏感性增加和远程访问而带来的云计算安全担忧。
  • 识别并评估适用于云基础设施和数据传输的关键安全机制。
  • 分析单个和组合安全控制在缓解云特定威胁方面的有效性。
  • 提出一种全面的、分层的安全模型,以提高云系统的弹性。

提出的方法

  • 应用端到端加密技术,保护数据在传输中和静态存储时的机密性。
  • 实施基于角色的访问控制(RBAC),以贯彻最小权限原则。
  • 集成入侵检测系统(IDS),以监控并响应可疑活动。
  • 使用安全的身份认证协议,防止未授权客户端访问。
  • 单独和组合评估安全控制措施,以评估其协同效应。
  • 采用标准密码原 primitive 和访问控制模型,以确保实用性与互操作性。

实验结果

研究问题

  • RQ1在云环境中,单个安全控制措施的独立表现如何?
  • RQ2组合多种安全机制对整体系统弹性有何影响?
  • RQ3哪种安全措施组合能对常见云威胁提供最有效的防护?
  • RQ4加密、访问控制和入侵检测如何共同提升数据的机密性和完整性?

主要发现

  • 组合安全机制在降低数据泄露风险方面显著优于单一控制措施。
  • 端到端加密在保护传输和存储中的数据方面被证明非常有效。
  • 基于角色的访问控制通过实施严格的权限策略,降低了未授权访问的可能性。
  • 入侵检测系统在测试场景中成功识别并预警了异常访问模式。
  • 分层安全模型在威胁检测和响应方面优于点对点解决方案。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。