Skip to main content
QUICK REVIEW

[论文解读] Security Issues on Cloud Computing

Harit Shah, Sharma Shankar Anandane|arXiv (Cornell University)|Aug 27, 2013
Security and Verification in Computing参考文献 4被引用 10
一句话总结

本文探讨了云计算中的关键安全挑战,重点关注多租户环境中数据机密性、完整性和访问控制的问题。它提出了一种高层级安全模型,以应对数据泄露、内部人员攻击和不安全接口等威胁,强调使用密码学控制和信任机制来减轻动态云基础设施中的风险。

ABSTRACT

The Cloud Computing concept offers dynamically scalable resources provisioned as a service over the Internet.Economic benefits are the main driver for the Cloud, since it promises the reduction of capital expenditure and operational expenditure.In order for this to become reality, however, there are still some challenges to be solved. Amongst these are security and trust issues, since the user data has to be released to the Cloud and thus leaves the protection sphere of the data owner. Most of the discussions on these topics are mainly driven by arguments related to organisational means. This paper focuses on various security issues arising from the usage of Cloud services and especially by the rapid development of Cloud computing arena. It also discusses basic security model followed by various High Level Security threats in the industry.

研究动机与目标

  • 识别并分析云计算服务采用过程中出现的主要安全问题。
  • 解决因数据存储和处理脱离用户直接控制而引发的信任缺失问题。
  • 提出一种结构化的安全模型,以缓解云环境中的高层级威胁。
  • 将关注重点从组织政策转向技术与密码学控制,以实现更强的安全保障。
  • 通过威胁建模和访问控制机制,为设计安全的云架构提供基础。

提出的方法

  • 本文基于常见云部署模式的威胁分析,构建了高层级安全模型。
  • 识别并分类了主要安全威胁,如数据泄露、不安全接口和内部人员攻击。
  • 该方法强调使用密码学技术,以确保在不可信云环境中的数据机密性和完整性。
  • 评估信任机制和访问控制策略,以防止未经授权的数据访问。
  • 该模型在多个层次集成安全控制:网络、存储和应用层。
  • 本研究借鉴现有框架,并将其映射到实际的云部署挑战中。

实验结果

研究问题

  • RQ1云计算环境中主要的技术安全威胁是什么?
  • RQ2当数据存储在第三方云基础设施中时,如何保护其机密性和完整性?
  • RQ3密码学控制在缓解云环境中内部和外部攻击方面发挥什么作用?
  • RQ4如何在云服务提供商与用户之间建立并维持信任?
  • RQ5仅依赖组织政策在云安全方面存在哪些局限性?

主要发现

  • 安全与信任问题仍是阻碍云计算广泛采用的最关键障碍。
  • 数据泄露和不安全接口是云环境中最主要的威胁之一。
  • 加密和访问控制等密码学机制对于保护多租户云中的数据至关重要。
  • 本文指出,仅靠组织政策不足以应对技术安全风险。
  • 提出了一种高层级安全模型,以指导分层安全控制的实施。
  • 本研究强调了制定标准化安全框架的必要性,以提升云服务的可信度。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。