Authors:
Moussa Ouedraogo
1
;
Eric Dubois
1
;
Djamel Khadraoui
1
;
Sebastien Poggi
2
and
Benoit Chenal
2
Affiliations:
1
Luxembourg Institute of Science and Technology, Luxembourg
;
2
Victor Buck Services S.A, Luxembourg
Keyword(s):
Cloud, Security Transparency, Mutual Auditability, Monitoring, Event Specification and Detection.
Related
Ontology
Subjects/Areas/Topics:
Cloud Computing
;
Cloud Computing Enabling Technology
;
Monitoring of Services, Quality of Service, Service Level Agreements
;
Security, Privacy, and Compliance Management
Abstract:
We propose an event-driven approach for the automated audit of cloud based services security. The proposed
approach is a solution to two of the intrinsic security issues of cloud based services, notably the need
of security transparency and mutual auditability amongst the stakeholders. We leverage a logic based event
specification language to represent patterns of events which occurrence can be evidence of security anomaly
or breach or simply a sign of a nefarious use of the cloud infrastructure by some of its users. The use of dedicated
algorithms for the detection of composite events coalesced with the definition of primitive events
structure based on XCCDF format ensures the reuse and interoperability with security audit tools based on
the Security Content and Automation Protocol-SCAP. The implementation and application of the approach
on a cloud service dealing with electronic archiving have demonstrated its feasibility and viability.