An Automated SMT-based Security Framework for Supporting Migrations in Cloud Composite Services - Inria - Institut national de recherche en sciences et technologies du numérique Access content directly
Conference Papers Year : 2022

An Automated SMT-based Security Framework for Supporting Migrations in Cloud Composite Services

Abstract

The growing maturity of orchestration languages is contributing to the elaboration of cloud composite services, whose resources may be deployed over different distributed infrastructures. These composite services are subject to changes over time, that are typically required to support cloud properties, such as scalability and rapid elasticity. In particular, the migration of their elementary resources may be triggered by performance constraints. However, changes induced by this migration may introduce vulnerabilities that may compromise the resources, or even the whole cloud service. In that context, we propose an automated SMT 1-based security framework for supporting the migration of resources in cloud composite services, and preventing the occurrence of new configuration vulnerabilities. We formalize the underlying security automation based on SMT solving, in order to assess the migrated resources and select adequate countermeasures , considering both endogenous and exogenous security mechanisms. We then evaluate its benefits and limits through large series of experiments based on a proof-ofconcept prototype implemented over the CVC4 commonly-used open-source solver. These experiments show a minimal overhead with regular operating systems deployed in cloud environments.
Fichier principal
Vignette du fichier
An_Automated_SMT_based_Security_Framework_for_Supporting_Migrations_in_Cloud_Composite_Services_Last_version.pdf (365.92 Ko) Télécharger le fichier
Origin : Files produced by the author(s)

Dates and versions

hal-03886057 , version 1 (07-12-2022)

Identifiers

  • HAL Id : hal-03886057 , version 1

Cite

Mohamed Oulaaffart, Remi Badonnel, Christophe Bianco. An Automated SMT-based Security Framework for Supporting Migrations in Cloud Composite Services. IEEE/IFIP Network Operations and Management Symposium, Apr 2022, Budapest, Hungary. ⟨hal-03886057⟩
49 View
47 Download

Share

Gmail Facebook X LinkedIn More