Home > Research > Publications & Outputs > Security policy verification for multi-domains ...

Links

Text available via DOI:

View graph of relations

Security policy verification for multi-domains in cloud systems

Research output: Contribution to Journal/MagazineJournal articlepeer-review

Published

Standard

Security policy verification for multi-domains in cloud systems. / Gouglidis, Antonios; Mavridis, Ioannis; Hu, Vincent C.
In: International Journal of Information Security, Vol. 13, No. 2, 01.04.2014, p. 97-111.

Research output: Contribution to Journal/MagazineJournal articlepeer-review

Harvard

Gouglidis, A, Mavridis, I & Hu, VC 2014, 'Security policy verification for multi-domains in cloud systems', International Journal of Information Security, vol. 13, no. 2, pp. 97-111. https://doi.org/10.1007/s10207-013-0205-x

APA

Gouglidis, A., Mavridis, I., & Hu, V. C. (2014). Security policy verification for multi-domains in cloud systems. International Journal of Information Security, 13(2), 97-111. https://doi.org/10.1007/s10207-013-0205-x

Vancouver

Gouglidis A, Mavridis I, Hu VC. Security policy verification for multi-domains in cloud systems. International Journal of Information Security. 2014 Apr 1;13(2):97-111. Epub 2013 Jul 17. doi: 10.1007/s10207-013-0205-x

Author

Gouglidis, Antonios ; Mavridis, Ioannis ; Hu, Vincent C. / Security policy verification for multi-domains in cloud systems. In: International Journal of Information Security. 2014 ; Vol. 13, No. 2. pp. 97-111.

Bibtex

@article{256e66f0c5864526ad17f32772a9154c,
title = "Security policy verification for multi-domains in cloud systems",
abstract = "The cloud is a modern computing paradigm with the ability to support a business model by providing multi-tenancy, scalability, elasticity, pay as you go and self-provisioning of resources by using broad network access. Yet, cloud systems are mostly bounded to single domains, and collaboration among different cloud systems is an active area of research. Over time, such collaboration schemas are becoming of vital importance since they allow companies to diversify their services on multiple cloud systems to increase both uptime and usage of services. The existence of an efficient management process for the enforcement of security policies among the participating cloud systems would facilitate the adoption of multi-domain cloud systems. An important issue in collaborative environments is secure inter-operation. Stemmed from the absence of relevant work in the area of cloud computing, we define a model checking technique that can be used as a management service/tool for the verification of multi-domain cloud policies. Our proposal is based on NIST's (National Institute of Standards and Technology) generic model checking technique and has been enriched with RBAC reasoning. Current approaches, in Grid systems, are capable of verifying and detect only conflicts and redundancies between two policies. However, the latter cannot overcome the risk of privileged user access in multi-domain cloud systems. In this paper, we provide the formal definition of the proposed technique and security properties that have to be verified in multi-domain cloud systems. Furthermore, an evaluation of the technique through a series of performance tests is provided.",
keywords = "Cloud computing, Collaboration, Multi-domain, RBAC, Secure inter-operation, Verification",
author = "Antonios Gouglidis and Ioannis Mavridis and Hu, {Vincent C.}",
year = "2014",
month = apr,
day = "1",
doi = "10.1007/s10207-013-0205-x",
language = "English",
volume = "13",
pages = "97--111",
journal = "International Journal of Information Security",
issn = "1615-5262",
publisher = "Springer Verlag",
number = "2",

}

RIS

TY - JOUR

T1 - Security policy verification for multi-domains in cloud systems

AU - Gouglidis, Antonios

AU - Mavridis, Ioannis

AU - Hu, Vincent C.

PY - 2014/4/1

Y1 - 2014/4/1

N2 - The cloud is a modern computing paradigm with the ability to support a business model by providing multi-tenancy, scalability, elasticity, pay as you go and self-provisioning of resources by using broad network access. Yet, cloud systems are mostly bounded to single domains, and collaboration among different cloud systems is an active area of research. Over time, such collaboration schemas are becoming of vital importance since they allow companies to diversify their services on multiple cloud systems to increase both uptime and usage of services. The existence of an efficient management process for the enforcement of security policies among the participating cloud systems would facilitate the adoption of multi-domain cloud systems. An important issue in collaborative environments is secure inter-operation. Stemmed from the absence of relevant work in the area of cloud computing, we define a model checking technique that can be used as a management service/tool for the verification of multi-domain cloud policies. Our proposal is based on NIST's (National Institute of Standards and Technology) generic model checking technique and has been enriched with RBAC reasoning. Current approaches, in Grid systems, are capable of verifying and detect only conflicts and redundancies between two policies. However, the latter cannot overcome the risk of privileged user access in multi-domain cloud systems. In this paper, we provide the formal definition of the proposed technique and security properties that have to be verified in multi-domain cloud systems. Furthermore, an evaluation of the technique through a series of performance tests is provided.

AB - The cloud is a modern computing paradigm with the ability to support a business model by providing multi-tenancy, scalability, elasticity, pay as you go and self-provisioning of resources by using broad network access. Yet, cloud systems are mostly bounded to single domains, and collaboration among different cloud systems is an active area of research. Over time, such collaboration schemas are becoming of vital importance since they allow companies to diversify their services on multiple cloud systems to increase both uptime and usage of services. The existence of an efficient management process for the enforcement of security policies among the participating cloud systems would facilitate the adoption of multi-domain cloud systems. An important issue in collaborative environments is secure inter-operation. Stemmed from the absence of relevant work in the area of cloud computing, we define a model checking technique that can be used as a management service/tool for the verification of multi-domain cloud policies. Our proposal is based on NIST's (National Institute of Standards and Technology) generic model checking technique and has been enriched with RBAC reasoning. Current approaches, in Grid systems, are capable of verifying and detect only conflicts and redundancies between two policies. However, the latter cannot overcome the risk of privileged user access in multi-domain cloud systems. In this paper, we provide the formal definition of the proposed technique and security properties that have to be verified in multi-domain cloud systems. Furthermore, an evaluation of the technique through a series of performance tests is provided.

KW - Cloud computing

KW - Collaboration

KW - Multi-domain

KW - RBAC

KW - Secure inter-operation

KW - Verification

U2 - 10.1007/s10207-013-0205-x

DO - 10.1007/s10207-013-0205-x

M3 - Journal article

AN - SCOPUS:84897101278

VL - 13

SP - 97

EP - 111

JO - International Journal of Information Security

JF - International Journal of Information Security

SN - 1615-5262

IS - 2

ER -