论文标题
云属性图:将云安全评估与静态代码分析连接
Cloud Property Graph: Connecting Cloud Security Assessments with Static Code Analysis
论文作者
论文摘要
在本文中,我们介绍云属性图(CloudPG),该图弥合了静态代码分析与云服务的运行时安全性评估之间的差距。 CloudPG能够解决部署在不同资源上的云应用程序之间的数据流,并使用运行时信息(例如加密设置)将图形化。为了提供云服务安全姿势的供应商和技术无关的表示,该图基于云资源的本体,其功能和安全功能。我们以示例表明,安全专家可以使用我们的CloudPG框架来识别其云部署中的弱点,这些弱点涵盖了多个供应商或技术,例如AWS,Azure和Kubernetes。这包括错误的配置,例如公共访问的储藏量或云服务中不需要的数据流,受到诸如GDPR之类的法规的限制。
In this paper, we present the Cloud Property Graph (CloudPG), which bridges the gap between static code analysis and runtime security assessment of cloud services. The CloudPG is able to resolve data flows between cloud applications deployed on different resources, and contextualizes the graph with runtime information, such as encryption settings. To provide a vendor- and technology-independent representation of a cloud service's security posture, the graph is based on an ontology of cloud resources, their functionalities and security features. We show, using an example, that our CloudPG framework can be used by security experts to identify weaknesses in their cloud deployments, spanning multiple vendors or technologies, such as AWS, Azure and Kubernetes. This includes misconfigurations, such as publicly accessible storages or undesired data flows within a cloud service, as restricted by regulations such as GDPR.