作者: Suryadipta Majumdar , Azadeh Tabiban , Meisam Mohammady , Alaa Oqaily , Yosr Jarraya
DOI: 10.1007/978-3-030-29962-0_12
关键词: Software security assurance 、 Enforcement 、 Key (cryptography) 、 Distributed computing 、 Proof of concept 、 Computer science 、 Dependency (UML) 、 Leverage (statistics) 、 Cloud computing 、 Process (engineering)
摘要: Security verification plays a vital role in providing users the needed security assurance many applications. However, applying existing tools for runtime enforcement may suffer from common limitation, i.e., causing significant delay to user requests. The key reason this limitation is that these are not specifically designed enforcement, especially dynamic and large-scale environment like clouds. In paper, we address issue by proposing proactive framework, namely, Proactivizer, transform into efficient solutions enforcement. Our main idea leverage as black boxes proactively trigger process based on dependency relationships among events. As proof of concept, apply Proactivizer several integrate it with OpenStack, popular cloud platform. We perform extensive experiments both simulated real environments results demonstrate effectiveness reducing response time significantly (e.g., within 9 ms verify 100,000 VMs up 99.9% reduction time).