FlowK: Information Flow Control for the Cloud

FlowK: Information Flow Control for the Cloud
复制标题

FlowK:云信息流控制

DOI:
10.1109/cloudcom.2014.11
复制
发表时间:
2014
期刊:
2014 IEEE 6th International Conference on Cloud Computing Technology and Science
影响因子:
--
通讯作者:
D. Eyers
D. Eyers
中科院分区:
--
文献类型:
--
作者:
Thomas Pasquier;J. Bacon;D. Eyers

文献摘要

被引文献

相似文献

安全问题被广泛视为采用云计算解决方案的障碍,尽管已经出现了大量的法律法规,但执行和展示合规性的技术基础仍然落后。我们的云安全网项目旨在证明信息流控制(IFC)可以增强现有的安全机制,并提供持续的扩展执行。云中更细粒度的应用程序级安全策略。我们提出了FlowK,一个Linux的内核模块,作为IFC可以提供云计算的概念证明的一部分。遵循策略-机制分离的原则,假设IFC策略在应用程序级别表达,FlowK提供在运行时执行IFC策略的机制。FlowK的设计最大限度地减少了提供IFC时对现有软件所需的更改。为了展示FlowK如何与云软件集成,我们设计并评估了一个框架,用于部署IFC感知的Web应用程序,适用于PaaS云中。
Security concerns are widely seen as an obstacle to the adoption of cloud computing solutions and although a wealth of law and regulation has emerged, the technical basis for enforcing and demonstrating compliance lags behind. Our Cloud Safety Net project aims to show that Information Flow Control (IFC) can augment existing security mechanisms and provide continuous enforcement of extended. Finer-grained application-level security policy in the cloud. We present FlowK, a loadable kernel module for Linux, as part of a proof of concept that IFC can be provided for cloud computing. Following the principle of policy-mechanism separation, IFC policy is assumed to be expressed at application level and FlowK provides mechanisms to enforce IFC policy at runtime. FlowK's design minimises the changes required to existing software when IFC is provided. To show how FlowK can be integrated with cloud software we have designed and evaluated a framework for deploying IFC-aware web applications, suitable for use in a PaaS cloud.