课题基金 / 基金详情

CloudSafetyNet: End-to-End Application Security in the Cloud

CloudSafetyNet: End-to-End Application Security in the Cloud
CloudSafetyNet:云中的端到端应用程序安全
批准号:
EP/K008129/1
负责人:
Peter Pietzuch
金额:
$66.78万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2013
资助国家:
英国
项目状态:
已结题
起止时间:
2013 至 --

项目摘要

项目成果

Peter Pietzuch的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Cloud computing promises to revolutionise how companies, research institutions and government organisations, including the National Health Service (NHS), offer applications and services to users in the digital economy. By consolidating many services as part of a shared ICT infrastructure operated by cloud providers, cloud computing can reduce management costs, shorten the deployment cycle of new services and improve energy efficiency. For example, the UK government's G-Cloud initiative aims to create a cloud ecosystem that will enable government organisations to deploy new applications rapidly, and to share and reuse existing services. Citizens will benefit from increased access to services, while public-sector ICT costs will be reduced.Security considerations, however, are a major issue holding back the widespread adoption of cloud computing: many organisations are concerned about the confidentiality and integrity of their users' data when hosted in third-party public clouds. Today's cloud providers struggle to give strong security guarantees that user data belonging to cloud tenants will be protected "end-to-end", i.e. across the entire workflow of a complex cloud-hosted distributed application. This is a challenging problem because data protection policies associated with applications usually require the strict isolation of certain data while permitting the sharing of other data. As an example, consider a local council with two applications on the G-Cloud: one for calculating unemployment benefits and one for receiving parking ticket fines, with both applications relying on a shared electoral roll database. How can the local council guarantee that data related to unemployment benefits will never be exposed to the parking fine application, even though both applications share a database and the cloud platform?The focus of the CloudSafetNet project is to rethink fundamentally how platform-as-a-service (PaaS) clouds should handle security requirements of applications. The overall goal is to provide the CloudSafetyNet middleware, a novel PaaS platform that acts as a "safety net", protecting against security violations caused by implementation flaws in applications ("intra-tenant security") or vulnerabilities in the cloud platform itself ("inter-tenant security"). CloudSafetyNet follows a "data-centric" security model: the integrity and confidentiality of application data is protected according to data flow policies -- agreements between cloud tenants and the provider specifying the permitted and prohibited exchanges of data between application components. It will enforce data flow policies through multiple levels of security mechanisms following a "defence-in-depth" strategy: based on policies, it creates "data compartments" that contain one or more components and isolate user data. A small privileged kernel, which is part of the middleware and constitutes a trusted computing base (TCB), tracks the flow of data between compartments and prevents flows that would violate policies. Previously such information flow control (IFC) models have been used successfully to enhance programming language, operating system and web application security. To make such a secure PaaS platform a reality, we plan to overcome a set of research challenges. We will explore how cloud application developers can express data-centric security policies that can be translated automatically into a set of data flow constraints in a distributed system. An open problem is how these constraints can be tied in with trusted enforcement mechanisms that exist in today's PaaS clouds. Addressing this will involve research into new lightweight isolation and sand-boxing techniques that allow the controlled execution of software components. In addition, we will advance software engineering methodology for secure cloud applications by developing new software architectures and design patterns that are compatible with compartmentalised data flow enforcement.
期刊论文(9)
专著(0)
科研奖励(0)
会议论文
BrowserFlow
浏览器流
DOI: 10.1145/2988336.2988345
发表时间: 2016
期刊:
影响因子: --
作者: [Papagiannis I]
通讯作者: Papagiannis I
DOI: --
发表时间: 2017-07
期刊:
影响因子: --
作者: [Joshua Lind;Christian Priebe;D. Muthukumaran;Dan O'Keeffe;Pierre-Louis Aublin;Florian Kelbert;T. Reiher-T.-R]
通讯作者: Joshua Lind;Christian Priebe;D. Muthukumaran;Dan O'Keeffe;Pierre-Louis Aublin;Florian Kelbert;T. Reiher-T.-R
DOI: 10.1145/3065913.3065917
发表时间: 2017-04
期刊: Proceedings of the 10th European Workshop on Systems Security
影响因子: --
作者: [David Goltzsche;C. Wulf;D. Muthukumaran;Konrad Rieck;P. Pietzuch;R. Kapitza]
通讯作者: David Goltzsche;C. Wulf;D. Muthukumaran;Konrad Rieck;P. Pietzuch;R. Kapitza
DOI: 10.1109/tnsm.2013.122313.130423
发表时间: 2014-01
期刊: IEEE Transactions on Network and Service Management
影响因子: 5.3
作者: [J. Bacon;D. Eyers;Thomas Pasquier;Jatinder Singh;I. Papagiannis;P. Pietzuch]
通讯作者: J. Bacon;D. Eyers;Thomas Pasquier;Jatinder Singh;I. Papagiannis;P. Pietzuch
Cloud Open Source Research Mobility Network
  • 批准号:
    EP/Y030346/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $7.58万
  • 财政年份:
    2023
  • 负责人:
    Peter Pietzuch
  • 依托单位:
CloudCAP: Capability-based Isolation for Cloud Native Applications
  • 批准号:
    EP/V000365/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $112.03万
  • 财政年份:
    2020
  • 负责人:
    Peter Pietzuch
  • 依托单位:
NaaS: Network-as-a-Service in the Cloud
  • 批准号:
    EP/K032968/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $84.88万
  • 财政年份:
    2013
  • 负责人:
    Peter Pietzuch
  • 依托单位:
CloudFilter: Practical Confinement of Sensitive Data Across Clouds
  • 批准号:
    EP/J020370/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $17.23万
  • 财政年份:
    2012
  • 负责人:
    Peter Pietzuch
  • 依托单位:
国内基金
海外基金
真菌特异的内吞作用相关蛋白End3发挥作用的结构研究
  • 批准号:
    32000859
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    24.0万元
  • 批准年份:
    2020
  • 负责人:
    王冬立
  • 依托单位:
从PBMC-β-END-μ-阿片受体途径探讨华蟾素治疗癌痛的外周机制
  • 批准号:
    81173612
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2011
  • 负责人:
    陈涛
  • 依托单位:
研究EB1(End-Binding protein 1)的癌基因特性及作用机制
  • 批准号:
    30672361
  • 项目类别:
    面上项目
  • 资助金额:
    24.0万元
  • 批准年份:
    2006
  • 负责人:
    徐宁志
  • 依托单位: