CloudFilter: Practical Confinement of Sensitive Data Across Clouds
CloudFilter: Practical Confinement of Sensitive Data Across Clouds
批准号:
EP/J020370/1
负责人:
Peter Pietzuch
金额:
$17.23万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2012
资助国家:
英国
项目状态:
已结题
起止时间:
2012 至 --
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Cloud computing aims to revolutionise traditional ways of service delivery. It enables companies, research institutions and government organisations to consolidate services in a shared ICT infrastructure supported by cloud providers. This reduces ownership and management costs, allows services to scale on-demand and improves energy efficiency. Security considerations, however, are a practical obstacle for the adoption of cloud computing. Cloud providers consolidate data from multiple services, which may result in wide-spread data disclosure when their security is compromised.Strong cloud security is hard to achieve because it requires that the cloud platform cannot be compromised by hosted applications and that applications belonging to different cloud tenants are isolated to prevent data leakage. Itis even harder for federated clouds, i.e. when a cloud provider uses another provider for some of its services. This is common in a Software-as-a-Service (SaaS) model, in which a provider offers a high-level service that can be reused by other providers. Both clients and cloud providers have an incentive to control the propagation of sensitive data. Clients are often legally responsible for data protection, and cloud providers want to prevent hosting sensitive data to avoid liability claims after security incidents.The CloudFilter project explores novel methods for exercising control over sensitive data propagation across multiple cloud providers. The targeted outcome is a practical solution that allows clients and cloud providers to control the sensitivity of data that is transferred across their systems and to prevent user actions that would violate data dissemination policies. Our key idea is to provide application-level proxies that transparently monitor data propagation from clients to cloud providers and between cloud providers. These proxies employ a data labelling scheme inspired by decentralised information flow control (DIFC) models, in which security classes express the sensitivity of transfered data. When crossing domain boundaries, labels are attached to data automatically based on data dissemination policies. Proxies verify labels according to domain policies to detect and prevent unauthorised data propagation between cloud domain domains.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
BrowserFlow
浏览器流
DOI:
10.1145/2988336.2988345
发表时间:
2016
期刊:
影响因子:
--
作者:
[Papagiannis I]
通讯作者:
Papagiannis I
DOI:
10.1145/2381913.2381931
发表时间:
2012-10
期刊:
影响因子:
--
作者:
[I. Papagiannis;P. Pietzuch]
通讯作者:
I. Papagiannis;P. Pietzuch
BrowserFlow: Preventing Accidental Data Disclosure in Web Browsers
BrowserFlow:防止 Web 浏览器中的意外数据泄露
DOI:
--
发表时间:
2016
期刊:
影响因子:
--
作者:
[Ioannis Papagiannis]
通讯作者:
Ioannis Papagiannis
Cloud Open Source Research Mobility Network
-
批准号:EP/Y030346/1
-
项目类别:Research Grant
-
资助金额:$7.58万
-
财政年份:2023
-
负责人:Peter Pietzuch
-
依托单位:
CloudCAP: Capability-based Isolation for Cloud Native Applications
-
批准号:EP/V000365/1
-
项目类别:Research Grant
-
资助金额:$112.03万
-
财政年份:2020
-
负责人:Peter Pietzuch
-
依托单位:
CloudSafetyNet: End-to-End Application Security in the Cloud
-
批准号:EP/K008129/1
-
项目类别:Research Grant
-
资助金额:$66.78万
-
财政年份:2013
-
负责人:Peter Pietzuch
-
依托单位:
NaaS: Network-as-a-Service in the Cloud
-
批准号:EP/K032968/1
-
项目类别:Research Grant
-
资助金额:$84.88万
-
财政年份:2013
-
负责人:Peter Pietzuch
-
依托单位:
Smart Flow - Extendable Event-Based Middleware
-
批准号:EP/F042469/1
-
项目类别:Research Grant
-
资助金额:$64.07万
-
财政年份:2008
-
负责人:Peter Pietzuch
-
依托单位:
DISSP: Dependable Internet-Scale Stream Processing
-
批准号:EP/F035217/1
-
项目类别:Research Grant
-
资助金额:$37.41万
-
财政年份:2008
-
负责人:Peter Pietzuch
-
依托单位:
海外基金