首页    期刊浏览 2024年11月30日 星期六
登录注册

文章基本信息

  • 标题:HOW SECURE IS YOUR CLOUD: CLASSIFICATION OF SECURITY THREATS AND COUNTERMEASURES WITHIN CLOUD COMPUTING?
  • 本地全文:下载
  • 作者:Sultan H. Almotiri ; Mohammed A. Al Ghamdi ; Atif Saeed
  • 期刊名称:International Journal of Computer Science and Network Security
  • 印刷版ISSN:1738-7906
  • 出版年度:2020
  • 卷号:20
  • 期号:8
  • 页码:228-241
  • 出版社:International Journal of Computer Science and Network Security
  • 摘要:Cloud computing is a contemporary cost-effective model in which the computing resources are dynamically scaled-up and scaled-down to customers, hosted within large- scale multi-tenant systems. These motivations can attract organizations to shift their sensitive data and critical infrastructure on cloud environments. But the cloud environments are facing a large number of challenges of misconfigurations, cyber-attacks, rootkits, malware instances etc. which manifest themselves as a serious threat to cloud environments. These threats noticeably decline the general trustworthiness, reliability and accessibility of the cloud. Security is the primary concern of a cloud service model. However, a number of significant challenges revealed that cloud environments are not as much secure as one could expect. cloud providers have implemented different security perimeters to mitigate these attacks, but these strategies are not impenetrable. A myriad of previous studies has demonstrated how cloud environment could be vulnerable to attacks through shared file systems, cache side-channels, or through compromising of hypervisor layer using rootkits. Thus, the threat of attacks is still possible because an attacker uses one VM to control or access other VMs on the same hypervisor. This paper presents the classification of security attacks across different cloud services. It also indicates attack types and risk levels associated with different cloud services. The attacks get more severe for lower layers where infrastructure and platform are involved. The intensity of these risk levels is also associated with security requirements of data encryption, multi-tenancy, data privacy, authentication and authorization for different cloud services.
  • 关键词:Cloud Computing; Cross-VM attacks; Countermeasures; Virtual Machine; Virtualization.
国家哲学社会科学文献中心版权所有