Repository logo
 

Information flow audit for PaaS clouds

Accepted version
Peer-reviewed

Repository DOI


Type

Conference Object

Change log

Authors

Pasquier, TFJM 
Bacon, J 
Eyers, D 

Abstract

© 2016 IEEE. With the rapid increase in uptake of cloud services, issues of data management are becoming increasingly prominent. There is a clear, outstanding need for the ability for specified policy to control and track data as it flows throughout cloud infrastructure, to ensure that those responsible for data are meeting their obligations. This paper introduces Information Flow Audit, an approach for tracking information flows within cloud infrastructure. This builds upon CamFlow (Cambridge Flow Control Architecture), a prototype implementation of our model for data-centric security in PaaS clouds. CamFlow enforces Information Flow Control policy both intra-machine at the kernel-level, and inter-machine, on message exchange. Here we demonstrate how CamFlow can be extended to provide data-centric audit logs akin to provenance metadata in a format in which analyses can easily be automated through the use of standard graph processing tools. This allows detailed understanding of the overall system. Combining a continuously enforced data-centric security mechanism with meaningful audit empowers tenants and providers to both meet and demonstrate compliance with their data management obligations.

Description

Keywords

4606 Distributed Computing and Systems Software, 46 Information and Computing Sciences, 4604 Cybersecurity and Privacy

Journal Title

Proceedings - 2016 IEEE International Conference on Cloud Engineering, IC2E 2016: Co-located with the 1st IEEE International Conference on Internet-of-Things Design and Implementation, IoTDI 2016

Conference Name

2016 IEEE International Conference on Cloud Engineering (IC2E)

Journal ISSN

2373-3845

Volume Title

Publisher

IEEE
Sponsorship
Engineering and Physical Sciences Research Council (EP/K011510/1)
This work was supported by UK Engineering and Physical Sciences Research Council grant EP/K011510 CloudSafetyNet: End-to-End Application Security in the Cloud. We acknowledge the support of Microsoft through the Microsoft Cloud Computing Research Centre.