|国家预印本平台
首页|Towards a Security Stress-Test for Cloud Configurations

Towards a Security Stress-Test for Cloud Configurations

Towards a Security Stress-Test for Cloud Configurations

来源:Arxiv_logoArxiv
英文摘要

Securing cloud configurations is an elusive task, which is left up to system administrators who have to base their decisions on ``trial and error'' experimentations or by observing good practices (e.g., CIS Benchmarks). We propose a knowledge, AND/OR, graphs approach to model cloud deployment security objects and vulnerabilities. In this way, we can capture relationships between configurations, permissions (e.g., CAP\_SYS\_ADMIN), and security profiles (e.g., AppArmor and SecComp), as first-class citizens. Such an approach allows us to suggest alternative and safer configurations, support administrators in the study of what-if scenarios, and scale the analysis to large scale deployments. We present an initial validation and illustrate the approach with three real vulnerabilities from known sources.

Fabio Massacci、Francesco Minna、Katja Tuma

安全科学计算技术、计算机技术

Fabio Massacci,Francesco Minna,Katja Tuma.Towards a Security Stress-Test for Cloud Configurations[EB/OL].(2022-05-28)[2025-05-13].https://arxiv.org/abs/2205.14498.点此复制

评论