The Experts below are selected from a list of 25374 Experts worldwide ranked by ideXlab platform
Mourad Debbabi - One of the best experts on this subject based on the ideXlab platform.
-
Auditing Security Compliance of the Virtualized Infrastructure
Cloud Security Auditing, 2019Co-Authors: Suryadipta Majumdar, Yosr Jarraya, Taous Madi, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang, Yushun Wang, Azadeh Tabiban, Momen Oqaily, Mourad DebbabiAbstract:This chapter presents a Security auditing approach for the cloud virtualized environment. More precisely, we focus primarily on virtual resources isolation based on structural properties (e.g., assignment of instances to physical hosts and the proper configuration of virtualization mechanisms), and consistency of the configurations in different layers of the cloud (infrastructure management layer, software-defined networking (SDN) controller layer, virtual layer, and physical layer). Although there already exist various efforts on cloud auditing (as shown in Chap. 2), to the best of our knowledge, none has facilitated automated auditing of structural settings of the virtual resources while taking into account the multi-layer aspects.
-
proactive verification of Security Compliance for clouds through pre computation application to openstack
European Symposium on Research in Computer Security, 2016Co-Authors: Suryadipta Majumdar, Yosr Jarraya, Taous Madi, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang, Mourad DebbabiAbstract:The verification of Security Compliance with respect to Security standards and policies is desirable to both cloud providers and users. However, the sheer size of a cloud implies a major challenge to be scalability and in particular response time. Most existing approaches are either after the fact or incur prohibitive delay in processing user requests. In this paper, we propose a scalable approach that can reduce the response time of online Security Compliance verification in large clouds to a practical level. The main idea is to start preparing for the costly verification proactively, as soon as the system is a few steps ahead of potential operations causing violations. We present detailed models and algorithms, and report real-life experiences and challenges faced while implementing our solution in OpenStack. We also conduct experiments whose results confirm the efficiency and scalability of our approach.
-
ESORICS (1) - Proactive Verification of Security Compliance for Clouds Through Pre-computation: Application to OpenStack
Computer Security – ESORICS 2016, 2016Co-Authors: Suryadipta Majumdar, Yosr Jarraya, Taous Madi, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang, Mourad DebbabiAbstract:The verification of Security Compliance with respect to Security standards and policies is desirable to both cloud providers and users. However, the sheer size of a cloud implies a major challenge to be scalability and in particular response time. Most existing approaches are either after the fact or incur prohibitive delay in processing user requests. In this paper, we propose a scalable approach that can reduce the response time of online Security Compliance verification in large clouds to a practical level. The main idea is to start preparing for the costly verification proactively, as soon as the system is a few steps ahead of potential operations causing violations. We present detailed models and algorithms, and report real-life experiences and challenges faced while implementing our solution in OpenStack. We also conduct experiments whose results confirm the efficiency and scalability of our approach.
-
Security Compliance auditing of identity and access management in the cloud application to openstack
IEEE International Conference on Cloud Computing Technology and Science, 2015Co-Authors: Suryadipta Majumdar, Yosr Jarraya, Taous Madi, Makan Pourzandi, Lingyu Wang, Yushun Wang, Mourad DebbabiAbstract:Cloud computing has seen a lot of interests and adoption lately. Nonetheless, the widespread adoption of cloud is still being hindered by the lack of transparency and accountability, which has traditionally been ensured through Security Compliance auditing techniques. Auditing in cloud, however, presents many new challenges in data collection and processing (e.g., data format inconsistency and lack of correlation due to the heterogeneity of cloud infrastructures) and in verification (e.g., prohibitive performance overhead due to the sheer scale of cloud infrastructures and their self-provisioning, elastic, and dynamic nature). In this paper, we propose a Security Compliance auditing framework for cloud, with special focus on identity and access management, and we implement and evaluate the framework based on OpenStack, one of the most popular cloud management systems. Our experimental results show that auditing with formal methods in large cloud environment is realistic (e.g., our auditing solution can handle 60 thousand users in less than one minute).
-
CloudCom - Security Compliance Auditing of Identity and Access Management in the Cloud: Application to OpenStack
2015 IEEE 7th International Conference on Cloud Computing Technology and Science (CloudCom), 2015Co-Authors: Suryadipta Majumdar, Yosr Jarraya, Taous Madi, Makan Pourzandi, Lingyu Wang, Yushun Wang, Mourad DebbabiAbstract:Cloud computing has seen a lot of interests and adoption lately. Nonetheless, the widespread adoption of cloud is still being hindered by the lack of transparency and accountability, which has traditionally been ensured through Security Compliance auditing techniques. Auditing in cloud, however, presents many new challenges in data collection and processing (e.g., data format inconsistency and lack of correlation due to the heterogeneity of cloud infrastructures) and in verification (e.g., prohibitive performance overhead due to the sheer scale of cloud infrastructures and their self-provisioning, elastic, and dynamic nature). In this paper, we propose a Security Compliance auditing framework for cloud, with special focus on identity and access management, and we implement and evaluate the framework based on OpenStack, one of the most popular cloud management systems. Our experimental results show that auditing with formal methods in large cloud environment is realistic (e.g., our auditing solution can handle 60 thousand users in less than one minute).
Booi Kam - One of the best experts on this subject based on the ideXlab platform.
-
Investigating the Role of Socio-organizational Factors in the Information Security Compliance in Organizations
2019Co-Authors: Ahmed Alkalbani, Hepu Deng, Booi KamAbstract:The increase reliance on information systems has created unprecedented challenges for organizations to protect their critical information from different Security threats that have direct consequences on the corporate liability, loss of credibility, and monetary damage. As a result, the Security of information has become critical in many organizations. This study investigates the role of socio-organizational factors by drawing the insights from the organizational theory literature in the adoption of information Security Compliance in organizations. Based on the analysis of the survey data collected from 294 employees, the study indicates management commitment, awareness and training, accountability, technology capability, technology compatibility, processes integration, and audit and monitoring have a significant positive impact on the adoption of information Security Compliance in organizations. The study contributes to the information Security Compliance research by exploring the criticality of socio-organizational factors at the organizational level for information Security Compliance.
-
The Influence of Organizational Enforcement on the Attitudes of Employees towards Information Security Compliance
2019 10th International Conference on Information and Communication Systems (ICICS), 2019Co-Authors: Ahmed Alkalbani, Hepu Deng, Booi KamAbstract:The increasing importance of combating information Security crimes has prompted individual organizations to enforce information Security Compliance. How such enforcement affects the attitude of individual employees towards information Security Compliance, however, is unclear. With the insights from the organizational theory literature, this study tests and validates a conceptual model that explores the impact of organizational enforcement on the attitude of employees using structural equation modelling based on the data collected from a survey of 294 employees in organizations. The study shows that both organizational Security culture and enforcement processes have a positive impact on the attitude of employees. The study further reveals that there is a positive relationship between organizational Security culture, Security technologies, and enforcement processes in enforcing Security Compliance. Such relationships form a mutual force for continually fostering a positive attitude of employees toward information Security Compliance in organizations.
-
Information Security Compliance in Organizations: An Institutional Perspective
Data and Information Management, 2017Co-Authors: Ahmed Alkalbani, Hepu Deng, Booi Kam, Xiaojuan ZhangAbstract:Abstract The increasing recognition of the importance of information Security has created institutional pressures on organizations to comply with information Security standards and policies for protecting their information. How such pressures influence information Security Compliance in organisations, however, is unclear. This paper presents an empirical study to investigate the impact of institutional pressures on information Security Compliance in organizations. With the use of structural equation modelling for analysing the data collected through an online survey, the study shows that coercive pressures, normative pressures, and mimetic pressures positively influence information Security Compliance in organizations. It reveals that the benefits of information Security Compliance motivate management to strengthen their commitments at information Security Compliance. Furthermore, the study finds out that social pressures do not have a significant impact on management commitments towards information Security Compliance. Theoretically this study contributes to the information Security research by better understanding how institutional pressures can be used for enhancing information Security Compliance in organizations. Practically this study informs information Security policy makers of the major institutional drivers for information Security Compliance.
-
Investigating the impact of institutional pressures on information Security Compliance in organizations
2017Co-Authors: Ahmed Alkalbani, Hepu Deng, Booi Kam, Xiajuan ZhangAbstract:The increasing threat to information Security has created institutional pressures on organizations to comply with information Security policies and standards. This paper presents an empirical study to investigate the impact of institutional pressures (coercive, normative, and mimetic) on information Security Compliance in organizations. The results show that coercive pressures that are manifested by regulatory agencies, normative pressures that are exerted through social pressures, and mimetic pressures that are manifested by Security benefits positively influence information Security Compliance in public organizations. Furthermore, the results reveal that regulation and Security benefits generate pressures on management to strengthen their commitments towards information Security Compliance in organizations. It is, however, worthwhile to notice that social pressures do not have a significant impact on management commitments towards information Security Compliance. The implications of this study indicate the criticality of institutional pressures for enhancing information Security Compliance in public organizations both directly and indirectly.
-
Investigating the Role of Socio-organizational Factors in the Information Security Compliance in Organizations
arXiv: Computers and Society, 2016Co-Authors: Ahmed Alkalbani, Hepu Deng, Booi KamAbstract:The increase reliance on information systems has created unprecedented challenges for organizations to protect their critical information from different Security threats that have direct consequences on the corporate liability, loss of credibility, and monetary damage. As a result, the Security of information has become a top priority in many organizations. This study investigates the role of socio-organizational factors by drawing the insights from the organizational theory literature in the adoption of information Security Compliance in organizations. Based on the analysis of the survey data collected from 294 employees from different organizations, the study indicates management commitment, awareness and training, accountability, technology capability, technology compatibility, processes integration, and audit and monitoring have a significant positive impact on the adoption of information Security Compliance in organizations. The study contributes to the information Security Compliance research by exploring the criticality of socio-organizational factors at the organizational level for information Security Compliance.
Suryadipta Majumdar - One of the best experts on this subject based on the ideXlab platform.
-
Auditing Security Compliance of the Virtualized Infrastructure
Cloud Security Auditing, 2019Co-Authors: Suryadipta Majumdar, Yosr Jarraya, Taous Madi, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang, Yushun Wang, Azadeh Tabiban, Momen Oqaily, Mourad DebbabiAbstract:This chapter presents a Security auditing approach for the cloud virtualized environment. More precisely, we focus primarily on virtual resources isolation based on structural properties (e.g., assignment of instances to physical hosts and the proper configuration of virtualization mechanisms), and consistency of the configurations in different layers of the cloud (infrastructure management layer, software-defined networking (SDN) controller layer, virtual layer, and physical layer). Although there already exist various efforts on cloud auditing (as shown in Chap. 2), to the best of our knowledge, none has facilitated automated auditing of structural settings of the virtual resources while taking into account the multi-layer aspects.
-
proactive verification of Security Compliance for clouds through pre computation application to openstack
European Symposium on Research in Computer Security, 2016Co-Authors: Suryadipta Majumdar, Yosr Jarraya, Taous Madi, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang, Mourad DebbabiAbstract:The verification of Security Compliance with respect to Security standards and policies is desirable to both cloud providers and users. However, the sheer size of a cloud implies a major challenge to be scalability and in particular response time. Most existing approaches are either after the fact or incur prohibitive delay in processing user requests. In this paper, we propose a scalable approach that can reduce the response time of online Security Compliance verification in large clouds to a practical level. The main idea is to start preparing for the costly verification proactively, as soon as the system is a few steps ahead of potential operations causing violations. We present detailed models and algorithms, and report real-life experiences and challenges faced while implementing our solution in OpenStack. We also conduct experiments whose results confirm the efficiency and scalability of our approach.
-
ESORICS (1) - Proactive Verification of Security Compliance for Clouds Through Pre-computation: Application to OpenStack
Computer Security – ESORICS 2016, 2016Co-Authors: Suryadipta Majumdar, Yosr Jarraya, Taous Madi, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang, Mourad DebbabiAbstract:The verification of Security Compliance with respect to Security standards and policies is desirable to both cloud providers and users. However, the sheer size of a cloud implies a major challenge to be scalability and in particular response time. Most existing approaches are either after the fact or incur prohibitive delay in processing user requests. In this paper, we propose a scalable approach that can reduce the response time of online Security Compliance verification in large clouds to a practical level. The main idea is to start preparing for the costly verification proactively, as soon as the system is a few steps ahead of potential operations causing violations. We present detailed models and algorithms, and report real-life experiences and challenges faced while implementing our solution in OpenStack. We also conduct experiments whose results confirm the efficiency and scalability of our approach.
-
auditing Security Compliance of the virtualized infrastructure in the cloud application to openstack
Conference on Data and Application Security and Privacy, 2016Co-Authors: Taous Madi, Suryadipta Majumdar, Yosr Jarraya, Makan Pourzandi, Yushun Wang, Lingyu WangAbstract:Cloud service providers typically adopt the multi-tenancy model to optimize resources usage and achieve the promised cost-effectiveness. Sharing resources between different tenants and the underlying complex technology increase the necessity of transparency and accountability. In this regard, auditing Security Compliance of the provider's infrastructure against standards, regulations and customers' policies takes on an increasing importance in the cloud to boost the trust between the stakeholders. However, virtualization and scalability make Compliance verification challenging. In this work, we propose an automated framework that allows auditing the cloud infrastructure from the structural point of view while focusing on virtualization-related Security properties and consistency between multiple control layers. Furthermore, to show the feasibility of our approach, we integrate our auditing system into OpenStack, one of the most used cloud infrastructure management systems. To show the scalability and validity of our framework, we present our experimental results on assessing several properties related to auditing inter-layer consistency, virtual machines co-residence, and virtual resources isolation.
-
CODASPY - Auditing Security Compliance of the Virtualized Infrastructure in the Cloud: Application to OpenStack
2016Co-Authors: Taous Madi, Suryadipta Majumdar, Yosr Jarraya, Makan Pourzandi, Yushun Wang, Lingyu WangAbstract:Cloud service providers typically adopt the multi-tenancy model to optimize resources usage and achieve the promised cost-effectiveness. Sharing resources between different tenants and the underlying complex technology increase the necessity of transparency and accountability. In this regard, auditing Security Compliance of the provider's infrastructure against standards, regulations and customers' policies takes on an increasing importance in the cloud to boost the trust between the stakeholders. However, virtualization and scalability make Compliance verification challenging. In this work, we propose an automated framework that allows auditing the cloud infrastructure from the structural point of view while focusing on virtualization-related Security properties and consistency between multiple control layers. Furthermore, to show the feasibility of our approach, we integrate our auditing system into OpenStack, one of the most used cloud infrastructure management systems. To show the scalability and validity of our framework, we present our experimental results on assessing several properties related to auditing inter-layer consistency, virtual machines co-residence, and virtual resources isolation.
Lingyu Wang - One of the best experts on this subject based on the ideXlab platform.
-
Auditing Security Compliance of the Virtualized Infrastructure
Cloud Security Auditing, 2019Co-Authors: Suryadipta Majumdar, Yosr Jarraya, Taous Madi, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang, Yushun Wang, Azadeh Tabiban, Momen Oqaily, Mourad DebbabiAbstract:This chapter presents a Security auditing approach for the cloud virtualized environment. More precisely, we focus primarily on virtual resources isolation based on structural properties (e.g., assignment of instances to physical hosts and the proper configuration of virtualization mechanisms), and consistency of the configurations in different layers of the cloud (infrastructure management layer, software-defined networking (SDN) controller layer, virtual layer, and physical layer). Although there already exist various efforts on cloud auditing (as shown in Chap. 2), to the best of our knowledge, none has facilitated automated auditing of structural settings of the virtual resources while taking into account the multi-layer aspects.
-
proactive verification of Security Compliance for clouds through pre computation application to openstack
European Symposium on Research in Computer Security, 2016Co-Authors: Suryadipta Majumdar, Yosr Jarraya, Taous Madi, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang, Mourad DebbabiAbstract:The verification of Security Compliance with respect to Security standards and policies is desirable to both cloud providers and users. However, the sheer size of a cloud implies a major challenge to be scalability and in particular response time. Most existing approaches are either after the fact or incur prohibitive delay in processing user requests. In this paper, we propose a scalable approach that can reduce the response time of online Security Compliance verification in large clouds to a practical level. The main idea is to start preparing for the costly verification proactively, as soon as the system is a few steps ahead of potential operations causing violations. We present detailed models and algorithms, and report real-life experiences and challenges faced while implementing our solution in OpenStack. We also conduct experiments whose results confirm the efficiency and scalability of our approach.
-
ESORICS (1) - Proactive Verification of Security Compliance for Clouds Through Pre-computation: Application to OpenStack
Computer Security – ESORICS 2016, 2016Co-Authors: Suryadipta Majumdar, Yosr Jarraya, Taous Madi, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang, Mourad DebbabiAbstract:The verification of Security Compliance with respect to Security standards and policies is desirable to both cloud providers and users. However, the sheer size of a cloud implies a major challenge to be scalability and in particular response time. Most existing approaches are either after the fact or incur prohibitive delay in processing user requests. In this paper, we propose a scalable approach that can reduce the response time of online Security Compliance verification in large clouds to a practical level. The main idea is to start preparing for the costly verification proactively, as soon as the system is a few steps ahead of potential operations causing violations. We present detailed models and algorithms, and report real-life experiences and challenges faced while implementing our solution in OpenStack. We also conduct experiments whose results confirm the efficiency and scalability of our approach.
-
auditing Security Compliance of the virtualized infrastructure in the cloud application to openstack
Conference on Data and Application Security and Privacy, 2016Co-Authors: Taous Madi, Suryadipta Majumdar, Yosr Jarraya, Makan Pourzandi, Yushun Wang, Lingyu WangAbstract:Cloud service providers typically adopt the multi-tenancy model to optimize resources usage and achieve the promised cost-effectiveness. Sharing resources between different tenants and the underlying complex technology increase the necessity of transparency and accountability. In this regard, auditing Security Compliance of the provider's infrastructure against standards, regulations and customers' policies takes on an increasing importance in the cloud to boost the trust between the stakeholders. However, virtualization and scalability make Compliance verification challenging. In this work, we propose an automated framework that allows auditing the cloud infrastructure from the structural point of view while focusing on virtualization-related Security properties and consistency between multiple control layers. Furthermore, to show the feasibility of our approach, we integrate our auditing system into OpenStack, one of the most used cloud infrastructure management systems. To show the scalability and validity of our framework, we present our experimental results on assessing several properties related to auditing inter-layer consistency, virtual machines co-residence, and virtual resources isolation.
-
CODASPY - Auditing Security Compliance of the Virtualized Infrastructure in the Cloud: Application to OpenStack
2016Co-Authors: Taous Madi, Suryadipta Majumdar, Yosr Jarraya, Makan Pourzandi, Yushun Wang, Lingyu WangAbstract:Cloud service providers typically adopt the multi-tenancy model to optimize resources usage and achieve the promised cost-effectiveness. Sharing resources between different tenants and the underlying complex technology increase the necessity of transparency and accountability. In this regard, auditing Security Compliance of the provider's infrastructure against standards, regulations and customers' policies takes on an increasing importance in the cloud to boost the trust between the stakeholders. However, virtualization and scalability make Compliance verification challenging. In this work, we propose an automated framework that allows auditing the cloud infrastructure from the structural point of view while focusing on virtualization-related Security properties and consistency between multiple control layers. Furthermore, to show the feasibility of our approach, we integrate our auditing system into OpenStack, one of the most used cloud infrastructure management systems. To show the scalability and validity of our framework, we present our experimental results on assessing several properties related to auditing inter-layer consistency, virtual machines co-residence, and virtual resources isolation.
Taous Madi - One of the best experts on this subject based on the ideXlab platform.
-
Auditing Security Compliance of the Virtualized Infrastructure
Cloud Security Auditing, 2019Co-Authors: Suryadipta Majumdar, Yosr Jarraya, Taous Madi, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang, Yushun Wang, Azadeh Tabiban, Momen Oqaily, Mourad DebbabiAbstract:This chapter presents a Security auditing approach for the cloud virtualized environment. More precisely, we focus primarily on virtual resources isolation based on structural properties (e.g., assignment of instances to physical hosts and the proper configuration of virtualization mechanisms), and consistency of the configurations in different layers of the cloud (infrastructure management layer, software-defined networking (SDN) controller layer, virtual layer, and physical layer). Although there already exist various efforts on cloud auditing (as shown in Chap. 2), to the best of our knowledge, none has facilitated automated auditing of structural settings of the virtual resources while taking into account the multi-layer aspects.
-
proactive verification of Security Compliance for clouds through pre computation application to openstack
European Symposium on Research in Computer Security, 2016Co-Authors: Suryadipta Majumdar, Yosr Jarraya, Taous Madi, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang, Mourad DebbabiAbstract:The verification of Security Compliance with respect to Security standards and policies is desirable to both cloud providers and users. However, the sheer size of a cloud implies a major challenge to be scalability and in particular response time. Most existing approaches are either after the fact or incur prohibitive delay in processing user requests. In this paper, we propose a scalable approach that can reduce the response time of online Security Compliance verification in large clouds to a practical level. The main idea is to start preparing for the costly verification proactively, as soon as the system is a few steps ahead of potential operations causing violations. We present detailed models and algorithms, and report real-life experiences and challenges faced while implementing our solution in OpenStack. We also conduct experiments whose results confirm the efficiency and scalability of our approach.
-
ESORICS (1) - Proactive Verification of Security Compliance for Clouds Through Pre-computation: Application to OpenStack
Computer Security – ESORICS 2016, 2016Co-Authors: Suryadipta Majumdar, Yosr Jarraya, Taous Madi, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang, Mourad DebbabiAbstract:The verification of Security Compliance with respect to Security standards and policies is desirable to both cloud providers and users. However, the sheer size of a cloud implies a major challenge to be scalability and in particular response time. Most existing approaches are either after the fact or incur prohibitive delay in processing user requests. In this paper, we propose a scalable approach that can reduce the response time of online Security Compliance verification in large clouds to a practical level. The main idea is to start preparing for the costly verification proactively, as soon as the system is a few steps ahead of potential operations causing violations. We present detailed models and algorithms, and report real-life experiences and challenges faced while implementing our solution in OpenStack. We also conduct experiments whose results confirm the efficiency and scalability of our approach.
-
auditing Security Compliance of the virtualized infrastructure in the cloud application to openstack
Conference on Data and Application Security and Privacy, 2016Co-Authors: Taous Madi, Suryadipta Majumdar, Yosr Jarraya, Makan Pourzandi, Yushun Wang, Lingyu WangAbstract:Cloud service providers typically adopt the multi-tenancy model to optimize resources usage and achieve the promised cost-effectiveness. Sharing resources between different tenants and the underlying complex technology increase the necessity of transparency and accountability. In this regard, auditing Security Compliance of the provider's infrastructure against standards, regulations and customers' policies takes on an increasing importance in the cloud to boost the trust between the stakeholders. However, virtualization and scalability make Compliance verification challenging. In this work, we propose an automated framework that allows auditing the cloud infrastructure from the structural point of view while focusing on virtualization-related Security properties and consistency between multiple control layers. Furthermore, to show the feasibility of our approach, we integrate our auditing system into OpenStack, one of the most used cloud infrastructure management systems. To show the scalability and validity of our framework, we present our experimental results on assessing several properties related to auditing inter-layer consistency, virtual machines co-residence, and virtual resources isolation.
-
CODASPY - Auditing Security Compliance of the Virtualized Infrastructure in the Cloud: Application to OpenStack
2016Co-Authors: Taous Madi, Suryadipta Majumdar, Yosr Jarraya, Makan Pourzandi, Yushun Wang, Lingyu WangAbstract:Cloud service providers typically adopt the multi-tenancy model to optimize resources usage and achieve the promised cost-effectiveness. Sharing resources between different tenants and the underlying complex technology increase the necessity of transparency and accountability. In this regard, auditing Security Compliance of the provider's infrastructure against standards, regulations and customers' policies takes on an increasing importance in the cloud to boost the trust between the stakeholders. However, virtualization and scalability make Compliance verification challenging. In this work, we propose an automated framework that allows auditing the cloud infrastructure from the structural point of view while focusing on virtualization-related Security properties and consistency between multiple control layers. Furthermore, to show the feasibility of our approach, we integrate our auditing system into OpenStack, one of the most used cloud infrastructure management systems. To show the scalability and validity of our framework, we present our experimental results on assessing several properties related to auditing inter-layer consistency, virtual machines co-residence, and virtual resources isolation.