Building Safe PaaS Clouds: a Survey on Security in Multitenant Software Platforms

Abstract : This paper surveys the risks brought by multitenancy in software platforms, along with the most prominent solutions proposed to address them. A multitenant platform hosts and executes software from several users (tenants). The platform must ensure that no malicious or faulty code from any tenant can interfere with the normal execution of other users' code or with the platform itself. This security requirement is specially relevant in Platform-as-a-Service (PaaS) clouds. PaaS clouds offer an execution environment based on some software platform. Unless PaaS systems are deemed as safe environments users will be reluctant to trust them to run any relevant application. This requires to take into account how multitenancy is handled by the software platform used as the basis of the PaaS offer. This survey focuses on two technologies that are or will be the platform-of-choice in many PaaS clouds: Java and .NET. We describe the security mechanisms they provide, study their limitations as multitenant platforms and analyze the research works that try to solve those limitations. We include in this analysis some standard container technologies (such as Enterprise Java Beans) that can be used to standardize the hosting environment of PaaS clouds. Also we include a brief discussion of Operating Systems (OSs) traditional security capacities and why OSs are unlikely to be chosen as the basis of PaaS offers. Finally, we describe some research initiatives that reinforce security by monitoring the execution of untrusted code, whose results can be of interest in multitenant systems.
Type de document :
Article dans une revue
Computers and Security, Elsevier, 2012, 31 (1), pp.96-108. 〈10.1016/j.cose.2011.10.006〉
Liste complète des métadonnées
Contributeur : Frédéric Desprez <>
Soumis le : mardi 27 août 2013 - 17:33:19
Dernière modification le : jeudi 8 février 2018 - 11:10:04

Lien texte intégral




Luis Rodero-Merino, Luis M. Vaquero, Eddy Caron, Frédéric Desprez, Adrian Muresan. Building Safe PaaS Clouds: a Survey on Security in Multitenant Software Platforms. Computers and Security, Elsevier, 2012, 31 (1), pp.96-108. 〈10.1016/j.cose.2011.10.006〉. 〈hal-00854655〉



Consultations de la notice