论文标题
迈向云配置的安全应力测试
Towards a Security Stress-Test for Cloud Configurations
论文作者
论文摘要
确保云配置是一项难以捉摸的任务,该任务留给了必须基于``试用和错误''实验或观察良好实践(例如CIS基准测试)的系统管理员。我们提出了一种知识和/或图形方法,以建模云部署安全对象和漏洞。这样,我们可以捕获配置,权限(例如Cap \ _sys \ _admin)和安全配置文件(例如Apparmor和Seccomp)之间的关系。这种方法使我们能够提出替代和更安全的配置,在研究什么情况下支持管理员,并将分析扩展到大规模部署。我们提出了初始验证,并用已知来源的三个实际漏洞说明了该方法。
Securing cloud configurations is an elusive task, which is left up to system administrators who have to base their decisions on ``trial and error'' experimentations or by observing good practices (e.g., CIS Benchmarks). We propose a knowledge, AND/OR, graphs approach to model cloud deployment security objects and vulnerabilities. In this way, we can capture relationships between configurations, permissions (e.g., CAP\_SYS\_ADMIN), and security profiles (e.g., AppArmor and SecComp), as first-class citizens. Such an approach allows us to suggest alternative and safer configurations, support administrators in the study of what-if scenarios, and scale the analysis to large scale deployments. We present an initial validation and illustrate the approach with three real vulnerabilities from known sources.