SCIFFS: Enabling Secure Third-Party Security Analytics using Serverless Computing

SCIFFS: Enabling Secure Third-Party Security Analytics using Serverless Computing
复制标题

SCIFFS:使用无服务器计算实现安全的第三方安全分析

DOI:
10.1145/3450569.3463567
复制
发表时间:
2021
期刊:
Proceedings of the 26th ACM Symposium on Access Control Models and Technologies
影响因子:
--
通讯作者:
Enck, William
Enck, William
中科院分区:
--
文献类型:
--
作者:
Polinsky, Isaac;Datta, Pubali;Bates, Adam;Enck, William

文献摘要

参考文献

被引文献

相似文献

第三方安全分析允许公司将威胁监控任务外包给专家团队,并避免内部安全运营中心的成本。通过分析来自许多客户的遥测数据,这些服务能够提供增强的洞察力,识别全球趋势并在威胁到达大多数客户之前发现威胁。不幸的是,同时驱动这些洞察力的聚合可能会暴露敏感的客户数据,如果它没有被正确地清理和跟踪。在这项工作中,我们提出了SCIFFS,一个自动化的信息流监控框架,用于防止敏感数据暴露在第三方安全分析平台。SCIFFS在无服务器环境中对客户数据进行分散的信息流控制,利用无服务器功能固有的多实例化性质来确保数据流的精确和轻量级跟踪。在广泛使用的OpenFaaS平台上,针对概念验证安全分析框架评估SCIFFS,我们证明了我们的解决方案支持常见的分析师工作流程(数据摄取,自定义仪表板,威胁狩猎),同时仅对事件摄取施加3.87%的运行时开销,聚合查询的开销随着数据库中记录的数量线性增长(例如,50,000条记录为18.75%,500,000条记录为104.27%)。因此,SCIFFS不仅为第三方安全分析建立了一个尊重隐私的模型,而且还强调了无服务器计算模型中安全敏感应用程序的机会。
Third-party security analytics allow companies to outsource threat monitoring tasks to teams of experts and avoid the costs of in-house security operations centers. By analyzing telemetry data from many clients these services are able to offer enhanced insights, identifying global trends and spotting threats before they reach most customers. Unfortunately, the aggregation that drives these insights simultaneously risks exposing sensitive client data if it is not properly sanitized and tracked. In this work, we present SCIFFS, an automated information flow monitoring framework for preventing sensitive data exposure in third-party security analytics platforms. SCIFFS performs decentralized information flow control over customer data it in a serverless setting, leveraging the innate polyinstantiated nature of serverless functions to assure precise and lightweight tracking of data flows. Evaluating SCIFFS against a proof-of-concept security analytics framework on the widely-used OpenFaaS platform, we demonstrate that our solution supports common analyst workflows data ingestion, custom dashboards, threat hunting) while imposing just 3.87% runtime overhead on event ingestion and the overhead on aggregation queries grows linearly with the number of records in the database (e.g., 18.75% for 50,000 records and 104.27% for 500,000 records) as compared to an insecure baseline. Thus, SCIFFS not only establishes a privacy-respecting model for third-party security analytics, but also highlights the opportunities for security-sensitive applications in the serverless computing model.
与政策无关的程序的分面执行
DOI: 10.1145/2465106.2465121
发表时间: 2013
期刊: ACM SIGOPS Oper. Syst. Rev.
影响因子: --
作者:
Thomas H. Austin;Jean Yang;C. Flanagan;Armando Solar
通讯作者: Armando Solar
迈向多元宇宙数据库
DOI: 10.1145/3317550.3321425
发表时间: 2019
期刊: HotOS '19: Proceedings of the Workshop on Hot Topics in Operating Systems
影响因子: --
作者:
Marzoev, Alana;Araújo, Lara Timbó;Schwarzkopf, Malte;Yagati, Samyukta;Kohler, Eddie;Morris, Robert;Kaashoek, M. Frans;Madden, Sam
通讯作者: Madden, Sam
DOI: 10.1145/3427228.3427665
发表时间: 2020-12
期刊: Proceedings of the 36th Annual Computer Security Applications Conference
影响因子: --
作者:
A. Sankaran;Pubali Datta;Adam Bates
通讯作者: A. Sankaran;Pubali Datta;Adam Bates
DOI: 10.1145/3290388
发表时间: 2019-01-01
影响因子: 1.8
作者:
Parker, James;Vazou, Niki;Hicks, Michael
通讯作者: Hicks, Michael
Haskell 中灵活的动态信息流控制
DOI: 10.1145/2034675.2034688
发表时间: 2012
影响因子: 1.5
作者:
D. Stefan;Alejandro Russo;John C. Mitchell;David Mazières
通讯作者: David Mazières