• DocumentCode
    267000
  • Title

    FlowK: Information Flow Control for the Cloud

  • Author

    Pasquier, Thomas F. J. M. ; Bacon, Jean ; Eyers, David

  • Author_Institution
    Comput. Lab., Univ. of Cambridge, Cambridge, UK
  • fYear
    2014
  • fDate
    15-18 Dec. 2014
  • Firstpage
    70
  • Lastpage
    77
  • Abstract
    Security concerns are widely seen as an obstacle to the adoption of cloud computing solutions and although a wealth of law and regulation has emerged, the technical basis for enforcing and demonstrating compliance lags behind. Our Cloud Safety Net project aims to show that Information Flow Control (IFC) can augment existing security mechanisms and provide continuous enforcement of extended. Finer-grained application-level security policy in the cloud. We present FlowK, a loadable kernel module for Linux, as part of a proof of concept that IFC can be provided for cloud computing. Following the principle of policy-mechanism separation, IFC policy is assumed to be expressed at application level and FlowK provides mechanisms to enforce IFC policy at runtime. FlowK´s design minimises the changes required to existing software when IFC is provided. To show how FlowK can be integrated with cloud software we have designed and evaluated a framework for deploying IFC-aware web applications, suitable for use in a PaaS cloud.
  • Keywords
    Linux; cloud computing; law; security of data; CloudSafetyNet project; FlowK; IFC-aware Web applications; Linux; PaaS cloud; cloud computing solutions; cloud software; compliance lags; finer-grained application-level security policy; information flow control; law; loadable kernel module; policy-mechanism separation; security concerns; technical basis; Context; Cryptography; Kernel; Sockets; Standards; IFC; Integrity; Kernel Module; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cloud Computing Technology and Science (CloudCom), 2014 IEEE 6th International Conference on
  • Conference_Location
    Singapore
  • Type

    conf

  • DOI
    10.1109/CloudCom.2014.11
  • Filename
    7037650