Cloud Computing Security: A Survey

被引:120
作者
Khalil, Issa M. [1 ]
Khreishah, Abdallah [2 ]
Azeem, Muhammad [3 ]
机构
[1] Qatar Fdn, QCRI, Doha, Qatar
[2] New Jersey Inst Technol, Newark Coll Engn, Dept Elect & Comp Engn, Newark, NJ 07102 USA
[3] United Arab Emirates Univ, Coll Informat Technol, Al Ain, U Arab Emirates
关键词
cloud computing; cloud security; security vulnerabilities; threats; attacks; insider attackers;
D O I
10.3390/computers3010001
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Cloud computing is an emerging technology paradigm that migrates current technological and computing concepts into utility-like solutions similar to electricity and water systems. Clouds bring out a wide range of benefits including configurable computing resources, economic savings, and service flexibility. However, security and privacy concerns are shown to be the primary obstacles to a wide adoption of clouds. The new concepts that clouds introduce, such as multi-tenancy, resource sharing and outsourcing, create new challenges to the security community. Addressing these challenges requires, in addition to the ability to cultivate and tune the security measures developed for traditional computing systems, proposing new security policies, models, and protocols to address the unique cloud security challenges. In this work, we provide a comprehensive study of cloud computing security and privacy concerns. We identify cloud vulnerabilities, classify known security threats and attacks, and present the state-of-the-art practices to control the vulnerabilities, neutralize the threats, and calibrate the attacks. Additionally, we investigate and identify the limitations of the current solutions and provide insights of the future security perspectives. Finally, we provide a cloud security framework in which we present the various lines of defense and identify the dependency levels among them. We identify 28 cloud security threats which we classify into five categories. We also present nine general cloud attacks along with various attack incidents, and provide effectiveness analysis of the proposed countermeasures.
引用
收藏
页码:1 / 35
页数:35
相关论文
共 96 条
[51]   A survey on gaps, threat remediation challenges and some thoughts for proactive attack detection in cloud computing [J].
Khorshed, Md. Tanzim ;
Ali, A. B. M. Shawkat ;
Wasimi, Saleh A. .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2012, 28 (06) :833-851
[52]  
Kim H., 2009, PROC VEE, P101
[53]   A Self-protection Mechanism against Stepping-stone Attacks for IaaS Clouds [J].
Kourai, Kenichi ;
Azumi, Takeshi ;
Chiba, Shigeru .
2012 9TH INTERNATIONAL CONFERENCE ON UBIQUITOUS INTELLIGENCE & COMPUTING AND 9TH INTERNATIONAL CONFERENCE ON AUTONOMIC & TRUSTED COMPUTING (UIC/ATC), 2012, :539-546
[54]  
Leandro M.A.P., 2012, ICN, P88
[55]  
Lin W., 2012, P 2012 32 INT C DIST, P417
[56]  
Liu S, 2010, PROCEEDINGS OF INTERNATIONAL CONFERENCE ON RESOURCE ENVIRONMENT AND INFORMATION TECHNOLOGY IN 2010 (REIT' 2010), P510
[57]  
Mahmood Z., 2011, 2011 International Conference on Emerging Intelligent Data and Web Technologies, P49, DOI 10.1109/EIDWT.2011.16
[58]  
Mareschal B., 1987, AIDE DECISION MULTIC, P175
[59]  
Martignoni L, 2009, LECT NOTES COMPUT SC, V5905, P178, DOI 10.1007/978-3-642-10772-6_14
[60]  
Mathisen E., 2011, 2011 5th IEEE International Conference on Digital Ecosystems and Technologies (DEST 2011), P208, DOI 10.1109/DEST.2011.5936627