Expression and enforcement of security policy for virtual resource allocation in IaaS cloud

6Citations
Citations of this article
19Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Many research works focus on the adoption of cloud infrastructure as a service (IaaS), where virtual machines (VM) are deployed on multiple cloud service providers (CSP). In terms of virtual resource allocation driven by security requirements, most of proposals take the aspect of cloud service customer (CSC) into account but do not address such requirements from CSP. Besides, it is a shared understanding that using a formal policy model to support the expression of security requirements can drastically ease the cloud resource management and conflict resolution. To address these theoretical limitations, our work is based on a formal model that applies organization-based access control (OrBAC) policy to IaaS resource allocation. In this paper, we first integrate the attribute-based security requirements in service level agreement (SLA) contract. After transformation, the security requirements are expressed by OrBAC rules and these rules are considered together with other non-security demands during the enforcement of resource allocation. We have implemented a prototype for VM scheduling in OpenStackbased multi-cloud environment and evaluated its performance.

Cite

CITATION STYLE

APA

Li, Y., Cuppens-Boulahia, N., Crom, J. M., Cuppens, F., & Frey, V. (2016). Expression and enforcement of security policy for virtual resource allocation in IaaS cloud. In IFIP Advances in Information and Communication Technology (Vol. 471, pp. 105–118). Springer New York LLC. https://doi.org/10.1007/978-3-319-33630-5_8

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free