Cloud Security Auditing

Finally, this book elaborates the design and implementation of a middleware as a pluggable interface to OpenStack for intercepting and verifying the legitimacy of user requests at runtime. The authors discuss how state-of-the-art security auditing solutions may help increase cloud tenants’ trust in...

Full description

Bibliographic Details
Main Authors: Majumdar, Suryadipta, Madi, Taous (Author), Wang, Yushun (Author), Tabiban, Azadeh (Author)
Format: eBook
Language:English
Published: Cham Springer International Publishing 2019, 2019
Edition:1st ed. 2019
Series:Advances in Information Security
Subjects:
Online Access:
Collection: Springer eBooks 2005- - Collection details see MPG.ReNa
LEADER 04070nmm a2200409 u 4500
001 EB001873005
003 EBX01000000000000001036376
005 00000000000000.0
007 cr|||||||||||||||||||||
008 190924 ||| eng
020 |a 9783030231286 
100 1 |a Majumdar, Suryadipta 
245 0 0 |a Cloud Security Auditing  |h Elektronische Ressource  |c by Suryadipta Majumdar, Taous Madi, Yushun Wang, Azadeh Tabiban, Momen Oqaily, Amir Alimohammadifar, Yosr Jarraya, Makan Pourzandi, Lingyu Wang, Mourad Debbabi 
250 |a 1st ed. 2019 
260 |a Cham  |b Springer International Publishing  |c 2019, 2019 
300 |a XI, 166 p. 75 illus., 10 illus. in color  |b online resource 
505 0 |a 1 Introduction -- 2 Literature Review -- 3 Auditing Security Compliance of Virtualized Infrastructure -- 4 Auditing Virtual Network Isolation across Cloud Layers -- 5 User-Level Runtime Security Auditing for the Cloud -- 6 Proactive Security Auditing in Clouds -- 7 Runtime Security Policy Enforcement in Clouds -- 8 Conclusion 
653 |a Computer Communication Networks 
653 |a Computer networks  
653 |a Computer Engineering and Networks 
653 |a Data protection 
653 |a Telecommunication 
653 |a Communications Engineering, Networks 
653 |a Computer engineering 
653 |a Data and Information Security 
700 1 |a Madi, Taous  |e [author] 
700 1 |a Wang, Yushun  |e [author] 
700 1 |a Tabiban, Azadeh  |e [author] 
041 0 7 |a eng  |2 ISO 639-2 
989 |b Springer  |a Springer eBooks 2005- 
490 0 |a Advances in Information Security 
028 5 0 |a 10.1007/978-3-030-23128-6 
856 4 0 |u https://doi.org/10.1007/978-3-030-23128-6?nosfx=y  |x Verlag  |3 Volltext 
082 0 |a 005.8 
520 |a Finally, this book elaborates the design and implementation of a middleware as a pluggable interface to OpenStack for intercepting and verifying the legitimacy of user requests at runtime. The authors discuss how state-of-the-art security auditing solutions may help increase cloud tenants’ trust in the service providers by providing assurance on the compliance with the applicable laws, regulations, policies, and standards. This book introduces the latest research results on both traditional retroactive auditing and novel (runtime and proactive) auditing techniques to serve different stakeholders in the cloud. This book covers security threats from different cloud abstraction levels and discusses a wide-range of security properties related to cloud-specific standards (e.g., Cloud Control Matrix (CCM) and ISO 27017). It also elaborates on the integration of security auditing solutions into real world cloud management platforms (e.g., OpenStack, Amazon AWS and GoogleGCP).  
520 |a This book provides a comprehensive review of the most up to date research related to cloud security auditing and discusses auditing the cloud infrastructure from the structural point of view, while focusing on virtualization-related security properties and consistency between multiple control layers. It presents an off-line automated framework for auditing consistent isolation between virtual networks in OpenStack-managed cloud spanning over overlay and layer 2 by considering both cloud layers’ views. A runtime security auditing framework for the cloud with special focus on the user-level including common access control and authentication mechanisms e.g., RBAC, ABAC and SSO is covered as well. This book also discusses a learning-based proactive security auditing system, which extracts probabilistic dependencies between runtime events and applies such dependencies to proactively audit and prevent security violations resulting from critical events.  
520 |a This book targets industrial scientists, who are working on cloud or security-related topics, as well as security practitioners, administrators, cloud providers and operators. Researchers and advanced-level students studying and working in computer science, practically in cloud security will also be interested in this book