Detection of access control violations in the secure sharing of cloud storage - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2018

Detection of access control violations in the secure sharing of cloud storage

Résumé

A cloud storage service implements security mechanisms to protect users data, including an access control mechanism to enable the data sharing. Thus, it is possible to define users permissions, granting the access only to authorized users. Existing solutions consider that the provider is honest but curious so that the designed mechanisms prevent the access to the files by the provider. However, the possibility of executing illegal transactions is not analyzed, and a malicious provider can perform transactions requested by unauthorized users, resulting in access control violations. In this paper, we propose monitoring and auditing mechanisms to detect these violations. As a result, new attacks are identified, especially those resulting from writing actions requested by users whose permissions were revoked. Colored Petri Nets (CPNs) are used to model and validate our proposal.
Fichier non déposé

Dates et versions

hal-01830866 , version 1 (05-07-2018)

Identifiants

  • HAL Id : hal-01830866 , version 1

Citer

Carlos André Batista De Carvalho, Rossana Maria de Castro Andrade, Nazim Agoulmine, Miguel Franklin de Castro. Detection of access control violations in the secure sharing of cloud storage. 8th International Conference on Cloud Computing and Services Science (CLOSER 2018), Mar 2018, Funchal, Portugal. pp.124--135. ⟨hal-01830866⟩
56 Consultations
0 Téléchargements

Partager

Gmail Facebook X LinkedIn More