Insider Threats to Cloud Computing: Directions for New Research Challenges

被引:59
作者
Claycomb, William R. [1 ]
Nicoll, Alex [1 ]
机构
[1] Carnegie Mellon Univ, Inst Software Engn, CERT Program, Pittsburgh, PA 15213 USA
来源
2012 IEEE 36TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC) | 2012年
关键词
insider; cloud; security;
D O I
10.1109/COMPSAC.2012.113
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Cloud computing related insider threats are often listed as a serious concern by security researchers, but to date this threat has not been thoroughly explored. We believe the fundamental nature of current insider threats will remain relatively unchanged in a cloud environment, but the paradigm does reveal new exploit possibilities. The common notion of a cloud insider as a rogue administrator of a service provider is discussed, but we also present two additional cloud-related insider risks: the insider who exploits a cloud-related vulnerability to steal information from a cloud system, and the insider who uses cloud systems to carry out an attack on an employer's local resources. We also characterize a hierarchy of administrators within cloud service providers, give examples of attacks from real insider threat cases, and show how the nature of cloud systems architectures enables attacks to succeed. Finally, we discuss our position on future cloud research.
引用
收藏
页码:387 / 394
页数:8
相关论文
共 24 条
[1]  
Alliance C. S., 2010, RSA C EUR
[2]  
[Anonymous], 2007, P 33 INT C VER LARG
[3]  
[Anonymous], IEEE COMP SOFTW APPL
[4]  
[Anonymous], TOP THREATS CLOUD CO
[5]  
C. for the Protection of National Infrastructure (CPNI), 2010, RISK ASS PERS SEC GU
[6]  
C. for the Protection of National Infrastructure (CPNI), 2011, PREEMPL SCREEN GOOD
[7]  
Cappelli D.M., 2009, COMMON SENSE GUIDE P
[8]  
Cappelli Dawn, 2012, The CERT Guide to Insider Threats: How to Prevent, Detect, and Respond to Information Technology Crimes (Theft, Sabotage, Fraud)
[9]  
Federal Bureau of Investigations, 2012, EC ESP SPOT POSS INS
[10]  
Greitzer F. L., 2012, 45 HAW INT C SYST SC