-
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
Module: Cloud Computing Security
Professor Trent Jaeger Penn State University
1
1
Module: Cloud Computing Security Professor Trent Jaeger Penn State - - PowerPoint PPT Presentation
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
1
1
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
2
2-1
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
2
2-2
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
2
2-3
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
2
2-4
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
2
2-5
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
2
2-6
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
2
2-7
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
2
2-8
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
2
2-9
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
2
2-10
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
2
2-11
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
3
3
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
4
4-1
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
4
4-2
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
4
4-3
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
5
Data Loss Incidents ‘06 ‘07 ‘08 ‘09 ‘10 ‘11
903 678 695 986 770 641
Incident Attack Vector External 54%
Unknown 7%
Insider 16% Accidental 23%
Credit: The Open Security Foundation datalossdb.org
5
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
6
6
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
7
7
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
8
8
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
9
Client
Scheduler Network Controller Cloud Database Message Queue Volume Store Image Store
Cloud API
Cloud Customer
Cloud Node
Instances
Cloud Vendor
9
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
10
10
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
11
11
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
12
Client
Service
12-1
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
12
Client Cloud Node Cloud Node Cloud Node Cloud Node
12-2
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
12
Client Cloud Node Cloud Node Cloud Node Cloud Node
12-3
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
12
Client Cloud Node Cloud Node Cloud Node Cloud Node
VM
12-4
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
12
Client Cloud Node Cloud Node Cloud Node Cloud Node
VM
12-5
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
VM
12
Client Cloud Node Cloud Node Cloud Node Cloud Node
VM
12-6
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
VM
12
Client Cloud Node Cloud Node Cloud Node Cloud Node
VM
12-7
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
VM
12
Client Cloud Node Cloud Node Cloud Node Cloud Node
VM VM VM
12-8
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
VM
12
Client Cloud Node Cloud Node Cloud Node Cloud Node
VM VM VM
12-9
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
13
13
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
14
!"#$%&'((& )*#+,&
3.&405*6076*,& 8.&$5,& 9.&($:"45;& <.&405*6076*,&
!"#$%&'()* +,-&".()*
!),/%0()*
=05*60/,>3'?=>3& =05*60/,>-'?=>-& '?=>3& '?=>-&
14
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
15
15
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
16
16
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
17
API Service Compute Service Database API Service
nova keypair-add mykey nova boot --key-name mykey
mykey : ssh-rsa ABC mykey : ssh-rsa ABC ssh-rsa ABC ssh-rsa DEF
Step 1 Step 2
17
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
18
Trust me with your code & data Cloud Provider Client You have to trust us as well Cloud operators
18
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
19
19
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
20
20
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
21
Helper& VM# VM# Vic&m# Beneficiary#
21
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
22
RFA$intensi*es$–$*me$in$ms$per&second& 196%$slowdown$ 86%$slowdown$ 60%$ Performance$ Improvement$
22
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
23
23
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
24
Service Client
24-1
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
24
Service Client
24-2
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
24
Service Client
24-3
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
24
Service Client
24-4
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
24
Service Client
24-5
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
24
Service
Data
Client
24-6
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
24
Service
Data
Client
24-7
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
24
Service Client
24-8
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
24
Service Client
24-9
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
25
25-1
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
25
25-2
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
25
25-3
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
25
25-4
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
25
25-5
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
25
25-6
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
25
25-7
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
26
26
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
27
4/19/13 Nuno Santos 13
! Check node
configurations
! Monitor attests
nodes in background
! Scalable policy
enforcement
! CP-ABE
client-side lib
Monitor
Customer
Policy-Sealed Data
+
seal unseal attest & send credential Datacenter
27
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
28
28
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
29
Management$ VM$(dom0)$
Work" VM" Work" VM" Work" VM"
29
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
30
Management$ VM$
30
Systems and Internet Infrastructure Security (SIIS) Laboratory Page
31
SDom0$
UDom0$ Client’s$metaBdomain$
Equipped$with$a$Trusted$Plaiorm$Module$(TPM)$chip$
31
Systems and Internet Infrastructure Security Laboratory (SIIS) Page
32
32