TY - GEN
T1 - CloudFence
T2 - 16th International Symposium on Research in Attacks, Intrusions, and Defenses, RAID 2013
AU - Pappas, Vasilis
AU - Kemerlis, Vasileios P.
AU - Zavou, Angeliki
AU - Polychronakis, Michalis
AU - Keromytis, Angelos D.
PY - 2013
Y1 - 2013
N2 - The risk of unauthorized private data access is among the primary concerns for users of cloud-based services. For the common setting in which the infrastructure provider and the service provider are different, users have to trust their data to both parties, although they interact solely with the latter. In this paper we propose CloudFence, a framework for cloud hosting environments that provides transparent, fine-grained data tracking capabilities to both service providers, as well as their users. CloudFence allows users to independently audit the treatment of their data by third-party services, through the intervention of the infrastructure provider that hosts these services. CloudFence also enables service providers to confine the use of sensitive data in well-defined domains, offering additional protection against inadvertent information leakage and unauthorized access. The results of our evaluation demonstrate the ease of incorporating CloudFence on existing real-world applications, its effectiveness in preventing a wide range of security breaches, and its modest performance overhead on real settings.
AB - The risk of unauthorized private data access is among the primary concerns for users of cloud-based services. For the common setting in which the infrastructure provider and the service provider are different, users have to trust their data to both parties, although they interact solely with the latter. In this paper we propose CloudFence, a framework for cloud hosting environments that provides transparent, fine-grained data tracking capabilities to both service providers, as well as their users. CloudFence allows users to independently audit the treatment of their data by third-party services, through the intervention of the infrastructure provider that hosts these services. CloudFence also enables service providers to confine the use of sensitive data in well-defined domains, offering additional protection against inadvertent information leakage and unauthorized access. The results of our evaluation demonstrate the ease of incorporating CloudFence on existing real-world applications, its effectiveness in preventing a wide range of security breaches, and its modest performance overhead on real settings.
KW - data auditing
KW - data flow tracking
KW - information confinement
UR - https://www.scopus.com/pages/publications/84888310971
U2 - 10.1007/978-3-642-41284-4_21
DO - 10.1007/978-3-642-41284-4_21
M3 - Conference contribution
AN - SCOPUS:84888310971
SN - 9783642412837
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 411
EP - 431
BT - Research in Attacks, Intrusions, and Defenses - 16th International Symposium, RAID 2013, Proceedings
PB - Springer Verlag
Y2 - 23 October 2013 through 25 October 2013
ER -