• DocumentCode
    173006
  • Title

    Progger: An Efficient, Tamper-Evident Kernel-Space Logger for Cloud Data Provenance Tracking

  • Author

    Ko, Ryan K. L. ; Will, Mark A.

  • Author_Institution
    Cyber Security Lab., Univ. of Waikato, Hamilton, New Zealand
  • fYear
    2014
  • fDate
    June 27 2014-July 2 2014
  • Firstpage
    881
  • Lastpage
    889
  • Abstract
    Cloud data provenance, or "what has happened to my data in the cloud", is a critical data security component which addresses pressing data accountability and data governance issues in cloud computing systems. In this paper, we present Progger (Provenance Logger), a kernel-space logger which potentially empowers all cloud stakeholders to trace their data. Logging from the kernel space empowers security analysts to collect provenance from the lowest possible atomic data actions, and enables several higher-level tools to be built for effective end-to-end tracking of data provenance. Within the last few years, there has been an increasing number of proposed kernel space provenance tools but they faced several critical data security and integrity problems. Some of these prior tools\´ limitations include (1) the inability to provide log tamper-evidence and prevention of fake/manual entries, (2) accurate and granular timestamp synchronisation across several machines, (3) log space requirements and growth, and (4) the efficient logging of root usage of the system. Progger has resolved all these critical issues, and as such, provides high assurance of data security and data activity audit. With this in mind, the paper will discuss these elements of high-assurance cloud data provenance, describe the design of Progger and its efficiency, and present compelling results which paves the way for Progger being a foundation tool used for data activity tracking across all cloud systems.
  • Keywords
    cloud computing; security of data; system monitoring; Progger; cloud computing systems; cloud data provenance tracking; data accountability; data activity audit; data activity tracking; data security component; kernel-space logger; Cloud computing; Data security; Kernel; Sockets; Synchronization; Virtual machining; Accountability; Cloud Computing; Data Provenance; Data Security; Tamper-evident logging; Time Synchronisation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cloud Computing (CLOUD), 2014 IEEE 7th International Conference on
  • Conference_Location
    Anchorage, AK
  • Print_ISBN
    978-1-4799-5062-1
  • Type

    conf

  • DOI
    10.1109/CLOUD.2014.121
  • Filename
    6973827