Skip to main content
QUICK REVIEW

[论文解读] Security and Privacy Concerns in Cloud-based Scientific and Business Workflows: A Systematic Review

Nafiseh Soveizi, Fatih Türkmen|arXiv (Cornell University)|Oct 5, 2022
Cloud Data Security Solutions被引用 5
一句话总结

本篇系统性综述识别了基于云的科学与业务工作流中的安全与隐私挑战,将现有解决方案按工作流生命周期阶段——执行、监控与自适应——进行分类。研究揭示了在动态、多方参与环境中,端到端保护、访问控制与信任管理方面存在关键缺口,并提出了未来在云原生工作流中保护敏感数据的关键开放研究问题。

ABSTRACT

Today, the number of data-intensive and compute-intensive applications like business and scientific workflows has dramatically increased, which made cloud computing more popular in the matter of delivering a large amount of computing resources on demand. On the other hand, security is a critical issue affecting the wide adoption of cloud technologies, especially for workflows that are mostly dealing with sensitive data and tasks. In this paper, we carry out a review of the state-of-the-art on how security and privacy concerns in scientific and business workflows in cloud environments are being addressed and identify the limitations and gaps in the current body of knowledge in this area. In this extensive literature review, we first present a classification of the state-of-the-art security solutions organized according to the phases of the workflow life cycle they target. Based on our findings, we provide a detailed review and classification of the most relevant available literature focusing on the execution, monitoring, and adaptation phases of workflows. Finally, we present a list of open research issues related to the security of cloud-based workflows and discuss them.

研究动机与目标

  • 分析当前关于保护基于云的科学与业务工作流的研究现状。
  • 根据工作流生命周期阶段对现有安全与隐私解决方案进行识别与分类。
  • 揭示当前在保护云环境中敏感数据与工作负载方面的方法所存在的局限性与研究空白。
  • 为工作流执行、监控与自适应阶段的威胁与对策提供结构化概述。
  • 突出未来在访问控制、信任管理以及动态云工作流中端到端安全方面的开放挑战。

提出的方法

  • 使用预设的搜索标准,在主要学术数据库与资源库中开展系统性文献综述。
  • 根据目标工作流生命周期阶段——执行、监控与自适应——对126项相关研究进行分类。
  • 分析各阶段中应用的访问控制、加密与审计技术等安全机制。
  • 将解决方案映射至具体威胁类别,包括数据泄露、未授权访问与内部威胁。
  • 将研究发现整合为安全控制的分类体系,并评估其在各工作流阶段的覆盖程度。
  • 识别出反复出现的局限性,如缺乏对细粒度访问控制的支持,以及与工作流编排框架集成不足。

实验结果

研究问题

  • RQ1基于云的科学与业务工作流中的主要安全与隐私威胁是什么?
  • RQ2现有解决方案在工作流生命周期阶段(执行、监控与自适应)中的分布情况如何?
  • RQ3最常采用的安全机制有哪些?它们在保护敏感数据方面的有效性如何?
  • RQ4当前研究在保护云工作流方面存在哪些关键局限性与空白?
  • RQ5在实现动态多租户云环境中端到端安全与隐私方面,仍存在哪些开放的研究挑战?

主要发现

  • 现有解决方案中,绝大多数集中于执行阶段,对监控与自适应阶段关注有限。
  • 访问控制机制虽常被提出,但通常缺乏在动态工作流中支持细粒度、基于策略的访问决策。
  • 端到端加密与数据匿名化技术应用不足,尤其在监控与日志阶段。
  • 信任管理与审计机制极少被集成进工作流编排系统,导致可见性与问责性方面的缺口。
  • 少数解决方案解决了内部攻击威胁,或在分布式云组件间提供全面的日志记录与可追溯性。
  • 在真实工作流部署中,缺乏用于比较安全解决方案有效性的标准化评估框架。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。