Title :
SecPlace: A Security-Aware Placement Model for Multi-tenant SaaS Environments
Author :
Eyad Saleh;Johannes Sianipar;Ibrahim Takouna;Christoph Meinel
Author_Institution :
Hasso Plattner Inst., Univ. of Potsdam, Potsdam, Germany
Abstract :
Software-as-a-Service (SaaS) is emerging as a new software delivery model, where the application and its associated data are hosted in the cloud. Due to the nature of SaaS and the cloud in general, where the data and the computation are beyond the control of the user, data privacy and security becomes a vital factor in this new paradigm. In multi-tenant SaaS applications, the tenants (i.e., Companies) become concerned about the confidentiality of their data since several tenants are consolidated onto a shared infrastructure (i.e., Databases). Consequently, two main questions raise. First, how to prohibit a tenant from accessing other´s data? Second, how to avoid the security threats from co-located competing tenants? In this paper, we address the second question. We present Sec Place, a resource allocation model designed to increase the level of security for tenants sharing the same infrastructure. Sec Place avoids hosting competing companies on the same database instance. We minimize the risk of co-resident tenants by preventing any two tenants of the same business type to be hosted on the same database server. Sec Place utilizes the usage of tenant subscription data, such as business type and tenant size and place the tenant accordingly. We conduct extensive experiments to validate our approach. The results show that our approach is practical, achieves its goal, and have a moderate complexity.
Keywords :
"Databases","Software as a service","Business","Security","Conferences","Algorithm design and analysis"
Conference_Titel :
Ubiquitous Intelligence and Computing, 2014 IEEE 11th Intl Conf on and IEEE 11th Intl Conf on and Autonomic and Trusted Computing, and IEEE 14th Intl Conf on Scalable Computing and Communications and Its Associated Workshops (UTC-ATC-ScalCom)
DOI :
10.1109/UIC-ATC-ScalCom.2014.31