The Experts below are selected from a list of 39 Experts worldwide ranked by ideXlab platform
Christoph Meinel - One of the best experts on this subject based on the ideXlab platform.
-
ICITST - Application of quantitative Security metrics in Cloud computing
2015 10th International Conference for Internet Technology and Secured Transactions (ICITST), 2015Co-Authors: Kennedy A. Torkura, Feng Cheng, Christoph MeinelAbstract:Security issues are still prevalent in Cloud computing particularly public Cloud. Efforts by Cloud Service Providers to secure out-sourced resources are not sufficient to gain trust from customers. Service Level Agreements (SLAs) are currently used to guarantee Security and privacy, however research into SLAs monitoring suggests levels of dissatisfaction from Cloud users. Accordingly, enterprises favor Private Clouds such as OpenStack as they offer more control and Security visibility. However, Private Clouds do not provide absolute Security, they share some Security challenges with public Clouds and eliminate other challenges. Security metrics based approaches such as quantitative Security assessments could be adopted to quantify Security value of Private and public Clouds. Software quantitative Security assessments provide extensive visibility into Security postures and help assess whether or not Security has improved or deteriorated. In this paper we focus on Private Cloud Security using OpenStack as a case study, we conduct a quantitative assessment of OpenStack based on empirical data. Our analysis is multi-faceted, covering OpenStack major releases and services. We employ Security metrics to determine the vulnerability density, vulnerability severity metrics and patching behavior. We show that OpenStack's Security has improved since inception, however concerted efforts are imperative for secure deployments, particularly in production environments.
-
Application of quantitative Security metrics in Cloud computing
2015 10th International Conference for Internet Technology and Secured Transactions (ICITST), 2015Co-Authors: Kennedy A. Torkura, Feng Cheng, Christoph MeinelAbstract:Security issues are still prevalent in Cloud computing particularly public Cloud. Efforts by Cloud Service Providers to secure out-sourced resources are not sufficient to gain trust from customers. Service Level Agreements (SLAs) are currently used to guarantee Security and privacy, however research into SLAs monitoring suggests levels of dissatisfaction from Cloud users. Accordingly, enterprises favor Private Clouds such as OpenStack as they offer more control and Security visibility. However, Private Clouds do not provide absolute Security, they share some Security challenges with public Clouds and eliminate other challenges. Security metrics based approaches such as quantitative Security assessments could be adopted to quantify Security value of Private and public Clouds. Software quantitative Security assessments provide extensive visibility into Security postures and help assess whether or not Security has improved or deteriorated. In this paper we focus on Private Cloud Security using OpenStack as a case study, we conduct a quantitative assessment of OpenStack based on empirical data. Our analysis is multi-faceted, covering OpenStack major releases and services. We employ Security metrics to determine the vulnerability density, vulnerability severity metrics and patching behavior. We show that OpenStack's Security has improved since inception, however concerted efforts are imperative for secure deployments, particularly in production environments.
Kennedy A. Torkura - One of the best experts on this subject based on the ideXlab platform.
-
ICITST - Application of quantitative Security metrics in Cloud computing
2015 10th International Conference for Internet Technology and Secured Transactions (ICITST), 2015Co-Authors: Kennedy A. Torkura, Feng Cheng, Christoph MeinelAbstract:Security issues are still prevalent in Cloud computing particularly public Cloud. Efforts by Cloud Service Providers to secure out-sourced resources are not sufficient to gain trust from customers. Service Level Agreements (SLAs) are currently used to guarantee Security and privacy, however research into SLAs monitoring suggests levels of dissatisfaction from Cloud users. Accordingly, enterprises favor Private Clouds such as OpenStack as they offer more control and Security visibility. However, Private Clouds do not provide absolute Security, they share some Security challenges with public Clouds and eliminate other challenges. Security metrics based approaches such as quantitative Security assessments could be adopted to quantify Security value of Private and public Clouds. Software quantitative Security assessments provide extensive visibility into Security postures and help assess whether or not Security has improved or deteriorated. In this paper we focus on Private Cloud Security using OpenStack as a case study, we conduct a quantitative assessment of OpenStack based on empirical data. Our analysis is multi-faceted, covering OpenStack major releases and services. We employ Security metrics to determine the vulnerability density, vulnerability severity metrics and patching behavior. We show that OpenStack's Security has improved since inception, however concerted efforts are imperative for secure deployments, particularly in production environments.
-
Application of quantitative Security metrics in Cloud computing
2015 10th International Conference for Internet Technology and Secured Transactions (ICITST), 2015Co-Authors: Kennedy A. Torkura, Feng Cheng, Christoph MeinelAbstract:Security issues are still prevalent in Cloud computing particularly public Cloud. Efforts by Cloud Service Providers to secure out-sourced resources are not sufficient to gain trust from customers. Service Level Agreements (SLAs) are currently used to guarantee Security and privacy, however research into SLAs monitoring suggests levels of dissatisfaction from Cloud users. Accordingly, enterprises favor Private Clouds such as OpenStack as they offer more control and Security visibility. However, Private Clouds do not provide absolute Security, they share some Security challenges with public Clouds and eliminate other challenges. Security metrics based approaches such as quantitative Security assessments could be adopted to quantify Security value of Private and public Clouds. Software quantitative Security assessments provide extensive visibility into Security postures and help assess whether or not Security has improved or deteriorated. In this paper we focus on Private Cloud Security using OpenStack as a case study, we conduct a quantitative assessment of OpenStack based on empirical data. Our analysis is multi-faceted, covering OpenStack major releases and services. We employ Security metrics to determine the vulnerability density, vulnerability severity metrics and patching behavior. We show that OpenStack's Security has improved since inception, however concerted efforts are imperative for secure deployments, particularly in production environments.
Feng Cheng - One of the best experts on this subject based on the ideXlab platform.
-
ICITST - Application of quantitative Security metrics in Cloud computing
2015 10th International Conference for Internet Technology and Secured Transactions (ICITST), 2015Co-Authors: Kennedy A. Torkura, Feng Cheng, Christoph MeinelAbstract:Security issues are still prevalent in Cloud computing particularly public Cloud. Efforts by Cloud Service Providers to secure out-sourced resources are not sufficient to gain trust from customers. Service Level Agreements (SLAs) are currently used to guarantee Security and privacy, however research into SLAs monitoring suggests levels of dissatisfaction from Cloud users. Accordingly, enterprises favor Private Clouds such as OpenStack as they offer more control and Security visibility. However, Private Clouds do not provide absolute Security, they share some Security challenges with public Clouds and eliminate other challenges. Security metrics based approaches such as quantitative Security assessments could be adopted to quantify Security value of Private and public Clouds. Software quantitative Security assessments provide extensive visibility into Security postures and help assess whether or not Security has improved or deteriorated. In this paper we focus on Private Cloud Security using OpenStack as a case study, we conduct a quantitative assessment of OpenStack based on empirical data. Our analysis is multi-faceted, covering OpenStack major releases and services. We employ Security metrics to determine the vulnerability density, vulnerability severity metrics and patching behavior. We show that OpenStack's Security has improved since inception, however concerted efforts are imperative for secure deployments, particularly in production environments.
-
Application of quantitative Security metrics in Cloud computing
2015 10th International Conference for Internet Technology and Secured Transactions (ICITST), 2015Co-Authors: Kennedy A. Torkura, Feng Cheng, Christoph MeinelAbstract:Security issues are still prevalent in Cloud computing particularly public Cloud. Efforts by Cloud Service Providers to secure out-sourced resources are not sufficient to gain trust from customers. Service Level Agreements (SLAs) are currently used to guarantee Security and privacy, however research into SLAs monitoring suggests levels of dissatisfaction from Cloud users. Accordingly, enterprises favor Private Clouds such as OpenStack as they offer more control and Security visibility. However, Private Clouds do not provide absolute Security, they share some Security challenges with public Clouds and eliminate other challenges. Security metrics based approaches such as quantitative Security assessments could be adopted to quantify Security value of Private and public Clouds. Software quantitative Security assessments provide extensive visibility into Security postures and help assess whether or not Security has improved or deteriorated. In this paper we focus on Private Cloud Security using OpenStack as a case study, we conduct a quantitative assessment of OpenStack based on empirical data. Our analysis is multi-faceted, covering OpenStack major releases and services. We employ Security metrics to determine the vulnerability density, vulnerability severity metrics and patching behavior. We show that OpenStack's Security has improved since inception, however concerted efforts are imperative for secure deployments, particularly in production environments.
Jorg Schwenk - One of the best experts on this subject based on the ideXlab platform.
-
how Private is your Private Cloud Security analysis of Cloud control interfaces
Cloud Computing Security Workshop, 2015Co-Authors: Dennis Felsch, Mario Heiderich, Frederic Schulz, Jorg SchwenkAbstract:The Security gateway between an attacker and a user's Private data is the Cloud Control Interface (CCI): If an attacker manages to get access to this interface, he controls the data. Several high-level data breaches originate here, the latest being the business failure of the British company Code Spaces. In such situations, using a Private Cloud is often claimed to be more secure than using a public Cloud. In this paper, we show that this Security assumption may not be justified: We attack Private Clouds through their rich, HTML5-based control interfaces, using well-known attacks on web interfaces (XSS, CSRF, and Clickjacking) combined with novel exploitation techniques for Infrastructure as a Service Clouds. We analyzed four open-source projects for Private IaaS Cloud deployment (Eucalyptus, OpenNebula, OpenStack, and openQRM) in default configuration. We were able to compromise the Security of three Cloud installations (Eucalyptus, OpenNebula, and openQRM) One of our attacks (OpenNebula) allowed us to gain root access to VMs even if full perimeter Security is enabled, i.e. if the Cloud control interface is only reachable from a certain segment of the company's network, and if all network traffic is filtered through a firewall. We informed all projects about the attack vectors and proposed mitigations. As a general recommendation, we propose to make web management interfaces for Private Clouds inaccessible from the Internet, and to include this technical requirement in the definition of a Private Cloud.
-
CCSW - How Private is Your Private Cloud?: Security Analysis of Cloud Control Interfaces
Proceedings of the 2015 ACM Workshop on Cloud Computing Security Workshop - CCSW '15, 2015Co-Authors: Dennis Felsch, Mario Heiderich, Frederic Schulz, Jorg SchwenkAbstract:The Security gateway between an attacker and a user's Private data is the Cloud Control Interface (CCI): If an attacker manages to get access to this interface, he controls the data. Several high-level data breaches originate here, the latest being the business failure of the British company Code Spaces. In such situations, using a Private Cloud is often claimed to be more secure than using a public Cloud. In this paper, we show that this Security assumption may not be justified: We attack Private Clouds through their rich, HTML5-based control interfaces, using well-known attacks on web interfaces (XSS, CSRF, and Clickjacking) combined with novel exploitation techniques for Infrastructure as a Service Clouds. We analyzed four open-source projects for Private IaaS Cloud deployment (Eucalyptus, OpenNebula, OpenStack, and openQRM) in default configuration. We were able to compromise the Security of three Cloud installations (Eucalyptus, OpenNebula, and openQRM) One of our attacks (OpenNebula) allowed us to gain root access to VMs even if full perimeter Security is enabled, i.e. if the Cloud control interface is only reachable from a certain segment of the company's network, and if all network traffic is filtered through a firewall. We informed all projects about the attack vectors and proposed mitigations. As a general recommendation, we propose to make web management interfaces for Private Clouds inaccessible from the Internet, and to include this technical requirement in the definition of a Private Cloud.
Keith Lewis - One of the best experts on this subject based on the ideXlab platform.
-
Private Cloud Security
Computer and Information Security Handbook (Third Edition), 2017Co-Authors: Keith LewisAbstract:This chapter covers the importance of Private Cloud Security, leveraging the advantages and disadvantages of the technology and how modern solutions have been able to provide working designs that make these solutions effective for Cloud Security–based infrastructures.
-
virtual Private Cloud Security
Computer and Information Security Handbook (Third Edition), 2017Co-Authors: Keith LewisAbstract:Abstract This chapter covers the overall concepts of virtual Private Cloud Security, the underlying details it functions, the importance of Security frameworks, and what is involved in their capabilities in Cloud infrastructure environments.