From system-centric to data-centric logging - Accountability, trust & security in cloud computing
From system-centric to data-centric logging - Accountability, trust & security in cloud computing
复制标题
从以系统为中心到以数据为中心的日志记录 - 责任、信任
DOI:
10.1109/dsr.2011.6026885
复制
发表时间:
2011
期刊:
影响因子:
--
通讯作者:
Bu
中科院分区:
文献类型:
--
作者:
R. Ko;M. Kirchberg;Bu
Cloud computing signifies a paradigm shift from owning computing systems to buying computing services. As a result of this paradigm shift, many key concerns such as the transparency of data transfer and access within the cloud, and the lack of clarity in data ownership were surfaced. To address these concerns, we propose a new way of approaching traditional security and trust problems: To adopt a detective, data-centric thinking instead of the classical preventive, system-centric thinking. While classical preventive approaches are useful, they play a catch-up game; often do not address the problems (i.e. data accountability, data retention, etc) directly. In this paper, we propose a data-centric, detective approach to increase trust and security of data in the cloud. Our framework, known as TrustCloud, contains a suite of techniques that address cloud security, trust and accountability from a detective approach at all levels of granularity. TrustCloud also extends detective techniques to policies and regulations governing IT systems.