DocumentCode :
604043
Title :
Engineering Intrusion Prevention Services for IaaS Clouds: The Way of the Hypervisor
Author :
Laniepce, Sylvie ; Lacoste, M. ; Kassi-Lahlou, M. ; Bignon, F. ; Lazri, Kahina ; Wailly, A.
Author_Institution :
Orange Labs., Cesson-Sévigné, France
fYear :
2013
fDate :
25-28 March 2013
Firstpage :
25
Lastpage :
36
Abstract :
Strong user expectations for protecting their cloud-hosted IT systems make enhanced security a key element for cloud adoption. This means that cloud infrastructure security should be guaranteed, but also that security monitoring services should be correctly designed to protect the user Virtual Machines (VMs), using Intrusion Detection and Prevention Services (IDPS). This paper gives an overview of available and emerging techniques for building intrusion monitoring services, analyzing their ability to address the VM protection requirements in a cloud context. While network- and host-based security monitoring are shown not to be well suited for the cloud, this paper makes a position statement, recommending a new monitoring approach, called hyper visor-based, as an alternative. This approach benefits from virtualization to monitor through the hyper visor, and from outside the user execution context, the security of computing, networking, and storage resources allocated to user VMs. Compared to traditional IDPS designs, hyper visor-based architectures are shown to be the most promising, greatly improving user VM security. This analysis also highlights the privileged role of the cloud provider to operate such type of IDPS, since it may perform integrated security monitoring as provider of both infrastructure and security services.
Keywords :
cloud computing; security of data; virtual machines; IaaS clouds; cloud adoption; cloud context; cloud hosted IT system; cloud infrastructure security; cloud provider; engineering intrusion prevention service; host based security monitoring; hypervisor; integrated security monitoring; intrusion detection; intrusion monitoring service; security monitoring service; strong user expectation; user execution context; user virtual machines security; Computer architecture; Context; Monitoring; Security; Software; Virtual machine monitors; Virtualization; Cloud Computing; Hypervisor; Intrusion Detection Services; Intrusion Prevention Services; VM Introspection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Service Oriented System Engineering (SOSE), 2013 IEEE 7th International Symposium on
Conference_Location :
Redwood City
Print_ISBN :
978-1-4673-5659-6
Type :
conf
DOI :
10.1109/SOSE.2013.27
Filename :
6525501
Link To Document :
بازگشت