- Title
- On the Design and Implementation of an Integrated Security Architecture for Cloud with Improved Resilience
- Creator
- Varadharajan, Vijay; Tupakula, Udaya
- Relation
- IEEE Transactions on Cloud Computing Vol. 5, Issue 3, p. 375-389
- Publisher Link
- http://dx.doi.org/10.1109/TCC.2016.2535320
- Publisher
- Institute of Electrical and Electronics Engineers (IEEE)
- Resource Type
- journal article
- Date
- 2017
- Description
- In this paper, we propose an integrated security architecture which combines policy based access control with intrusion detection techniques and trusted computing technologies for securing distributed applications running on virtualised systems. Our security architecture incorporates access control security policies for secure interactions between applications and virtual machines in different physical virtualized servers. It provides intrusion detection and trusted attestation techniques to detect and counteract dynamic attacks in an efficient manner. We demonstrate how this integrated security architecture is used to secure the life cycle of virtual machines including dynamic hosting and allocation of resources as well as migration of virtual machines across different physical servers. We discuss the implementation of the developed architecture and show how the architecture can counteract attack scenarios involving malicious users exploiting vulnerabilities to achieve privilege escalation and then using the compromised machines to generate further attacks. The feedback between the various security components of our security architecture plays a critical role in detecting sophisticated, dynamically changing attacks, thereby increasing the resilience of the overall secure system.
- Subject
- integrated security architecture; access control; intrusion detection; trusted computing; resilience
- Identifier
- http://hdl.handle.net/1959.13/1442198
- Identifier
- uon:41624
- Identifier
- ISSN:2168-7161
- Language
- eng
- Reviewed
- Hits: 414
- Visitors: 412
- Downloads: 0
Thumbnail | File | Description | Size | Format |
---|