论文标题
云基础设施的连续风险评估方法
A Continuous Risk Assessment Methodology for Cloud Infrastructures
论文作者
论文摘要
云系统是动态环境,使得很难跟踪资源所面临的安全风险。传统上,进行了风险评估,以评估现有威胁;但是,在如此动态的环境中,他们的结果迅速过时。在本文中,我们提出了对云基础架构的传统风险评估方法的改编,这些方法可以通过持续的,自动应用其结果进行手动,深入分析。这两个部分与新颖的威胁性概况定义相关联,该定义可以重复描述基于资产和云提供商跨资产和云提供商常见的属性的配置弱点。这样,可以自动确定所有具有相同属性的资源,包括新的和修改的资源。我们还提出了一个原型实现,该实现将自动评估基础架构作为云系统的代码模板,以应对一组威胁概况,并评估其性能。我们的方法不仅使组织能够重复其威胁分析结果,还可以协作其发展,例如与公共社区。为此,我们提出了一个最初的威胁性配置文件的开源存储库。
Cloud systems are dynamic environments which make it difficult to keep track of security risks that resources are exposed to. Traditionally, risk assessment is conducted for individual assets to evaluate existing threats; their results, however, are quickly outdated in such a dynamic environment. In this paper, we propose an adaptation of the traditional risk assessment methodology for cloud infrastructures which loosely couples manual, in-depth analyses with continuous, automatic application of their results. These two parts are linked by a novel threat profile definition that allows to reusably describe configuration weaknesses based on properties that are common across assets and cloud providers. This way, threats can be identified automatically for all resources that exhibit the same properties, including new and modified ones. We also present a prototype implementation which automatically evaluates an infrastructure as code template of a cloud system against a set of threat profiles, and we evaluate its performance. Our methodology not only enables organizations to reuse their threat analysis results, but also to collaborate on their development, e.g. with the public community. To that end, we propose an initial open-source repository of threat profiles.