Securing Open Source Clouds Using Models
Irum Rauf ({\AA}bo Akademi University, Turku, Finland), Elena, Troubitsyna ({\AA}bo Akademi University, Turku, Finland)

TL;DR
This paper presents an automated model-driven approach to verify and validate the security of open source cloud frameworks like OpenStack, even with frequent updates, by modeling APIs and security requirements.
Contribution
It introduces a novel automated verification method using models and wrappers to ensure security properties in open source cloud frameworks amidst frequent releases.
Findings
Automated security verification of OpenStack Keystone achieved.
Model-driven approach effectively detects security violations.
Implementation in Django demonstrates practical applicability.
Abstract
The widespread adoption of cloud computing has resulted in the proliferation of open source cloud computing frameworks that give more control to enterprises over their data and networks. Though the benefits of open source software are widely recognized, there is a growing concern over their security assurance. Often open source software is a subject of frequent updates. The updates might introduce or remove a variety of features and hence violate security properties of the previous releases. Obviously, a manual inspection of security would be prohibitively slow and inefficient. In this work, we propose an automated approach that can help developers to assure the security of open source cloud framework even in the presence of frequent releases. Our methodology consists of creating a (stateful) wrapper that emulates the usage scenarios with explicit representation of security and…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware System Performance and Reliability · Scientific Computing and Data Management · Cloud Data Security Solutions
