From system-centric to data-centric logging - Accountability, trust & security in cloud computing

From system-centric to data-centric logging - Accountability, trust & security in cloud computing
复制标题

从以系统为中心到以数据为中心的日志记录 - 责任、信任

DOI:
10.1109/dsr.2011.6026885
复制
发表时间:
2011
期刊:
2011 Defense Science Research Conference and Expo (DSR)
影响因子:
--
通讯作者:
Bu
Bu
中科院分区:
--
文献类型:
--
作者:
R. Ko;M. Kirchberg;Bu

文献摘要

被引文献

相似文献

云计算意味着从拥有计算系统到购买计算服务的范式转变。由于这种模式的转变,许多关键问题浮出水面,例如云中数据传输和访问的透明度,以及数据所有权缺乏明确性。为了解决这些问题,我们提出了一种解决传统安全和信任问题的新方法:采用以数据为中心的侦探思维,而不是传统的以系统为中心的预防性思维。虽然传统的预防方法是有用的,但它们只是一种追赶游戏;往往不能直接解决问题(即数据问责制、数据保留等)。在本文中,我们提出了一种以数据为中心的检测方法,以提高云中数据的信任和安全性。我们的框架称为TrustCloud,包含一套技术,可以从各个粒度级别的检测方法解决云安全,信任和问责制。TrustCloud还将检测技术扩展到管理IT系统的政策和法规。
Cloud computing signifies a paradigm shift from owning computing systems to buying computing services. As a result of this paradigm shift, many key concerns such as the transparency of data transfer and access within the cloud, and the lack of clarity in data ownership were surfaced. To address these concerns, we propose a new way of approaching traditional security and trust problems: To adopt a detective, data-centric thinking instead of the classical preventive, system-centric thinking. While classical preventive approaches are useful, they play a catch-up game; often do not address the problems (i.e. data accountability, data retention, etc) directly. In this paper, we propose a data-centric, detective approach to increase trust and security of data in the cloud. Our framework, known as TrustCloud, contains a suite of techniques that address cloud security, trust and accountability from a detective approach at all levels of granularity. TrustCloud also extends detective techniques to policies and regulations governing IT systems.