Towards Cloud-Aware Vulnerability Assessments | IEEE Conference Publication | IEEE Xplore

Towards Cloud-Aware Vulnerability Assessments


Abstract:

Vulnerability assessments are best practices for computer security and requirements for regulatory compliance. Potential and existing security holes can be identified dur...Show More

Abstract:

Vulnerability assessments are best practices for computer security and requirements for regulatory compliance. Potential and existing security holes can be identified during vulnerability assessments and security breaches could be averted. However, the unique nature of cloud computing environments requires more dynamic assessment techniques. The proliferation of cloud services and cloud-aware applications introduce more cloud vulnerabilities. But, current measures for identification, mitigation and prevention of cloud vulnerabilities do not suffice. Our investigations indicate a possible reason for this inefficiency to lapses in availability of precise, cloud vulnerability information. We observed also that most research efforts in the context of cloud vulnerability concentrate on IaaS, leaving other cloud models largely unattended. Similarly, most cloud assessment efforts tackle general cloud vulnerabilities rather than cloud specific vulnerabilities. Yet, mitigating cloud specific vulnerabilities is important for cloud security. Hence, this paper proposes a new approach that addresses the mentioned issues by monitoring, acquiring and adapting publicly available cloud vulnerability information for effective vulnerability assessments. We correlate vulnerability information from public vulnerability databases and develop Network Vulnerability Tests for specific cloud vulnerabilities. We have implemented, evaluated and verified the suitability of our approach.
Date of Conference: 23-27 November 2015
Date Added to IEEE Xplore: 08 February 2016
Electronic ISBN:978-1-4673-9721-6
Conference Location: Bangkok, Thailand

Contact IEEE to Subscribe

References

References is not available for this document.