资源描述:
《云计算中存在的安全问题》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、SecurityIssuesinCloudComputingAnyaKimNavalResearchLabanya.kim@nrl.navy.milTalkObjectivesPresentcloudissues/characteristicsthatcreateinterestingsecurityproblemsIdentifyafewsecurityissueswithinthisframeworkProposesomeapproachestoaddressingtheseissuesPreliminar
2、yideastothinkaboutCloudComputingBackgroundFeaturesUseofinternet-basedservicestosupportbusinessprocessRentIT-servicesonautility-likebasisAttributesRapiddeploymentLowstartupcosts/capitalinvestmentsCostsbasedonusageorsubscriptionMulti-tenantsharingofservices/re
3、sourcesEssentialcharacteristicsOndemandself-serviceUbiquitousnetworkaccessLocationindependentresourcepoolingRapidelasticityMeasuredservice“Cloudcomputingisacompilationofexistingtechniquesandtechnologies,packagedwithinanewinfrastructureparadigmthatoffersimpro
4、vedscalability,elasticity,businessagility,fasterstartuptime,reducedmanagementcosts,andjust-in-timeavailabilityofresources”Source:NISTCloudModelsDeliveryModelsSaaSPaaSIaaSDeploymentModelsPrivatecloudCommunitycloudPubliccloudHybridcloudWeproposeonemoreModel:Ma
5、nagementModels(trustandtenancyissues)Self-managed3rdpartymanaged(e.g.publiccloudsandVPC)Source:NISTCloudComputing:AMassiveConcentrationofResourcesAlsoamassiveconcentrationofriskexpectedlossfromasinglebreachcanbesignificantlylargerconcentrationof“users”repres
6、entsaconcentrationofthreats“Ultimately,youcanoutsourceresponsibilitybutyoucan’toutsourceaccountability.”FromJohnMcDermott,ACSAC09CloudComputing:whoshoulduseit?Cloudcomputingdefinitelymakessenseifyourownsecurityisweak,missingfeatures,orbelowaverage.Ultimately
7、,ifthecloudprovider’ssecuritypeopleare“better”thanyours(andleveragedatleastasefficiently),theweb-servicesinterfacesdon’tintroducetoomanynewvulnerabilities,andthecloudprovideraimsatleastashighasyoudo,atsecuritygoals,thencloudcomputinghasbettersecurity.FromJoh
8、nMcDermott,ACSAC09ProblemsAssociatedwithCloudComputingMostsecurityproblemsstemfrom:LossofcontrolLackoftrust(mechanisms)Multi-tenancyTheseproblemsexistmainlyin3rdpartymanagementmodelsSelf-managed