Skip to main navigation Skip to search Skip to main content

Survey on Insider Threats to Cloud Computing

  • Guo Feng Wang
  • , Chuan Yi Liu*
  • , He Zhong Pan
  • , Bin Xing Fang
  • *Corresponding author for this work
  • Beijing University of Posts and Telecommunications
  • Harbin Institute of Technology Shenzhen
  • University of Electronic Science and Technology of China

Research output: Contribution to journalArticlepeer-review

Abstract

The division of data ownership and data management is regarded as the key characteristics of cloud computing. Customers outsource their data to the cloud and need to use cloud computing platform for data management, as a result losing direct control over the data. The introduction of cloud computing model has brought some new security issues and challenges, such as malicious cloud administrator, security vulnerabilities and improper access interface. So insider threats become more crucial, especially with the cloud administrators gaining more control on customers' virtual machines and data in reality. How to defend against malicious insiders, especially who have priorities to access or steal customers' data and computation resources, has become a challenging problem as well as a common focus of attention in both academia and industry in recent years. For further study of the insider threats in cloud computing model, making systematic summary from ways and means to deal with, and promoting domestic research in this direction, this paper firstly summarizes the major types of internal threats in the cloud environment, and takes an experimental approach to demonstrate typical insider vulnerabilities and possible actionable attacks. This paper summarizes and proposes three approaches to deal with insider threats in the cloud, as: user & entity behavior analysis and evaluation, cloud administration priority division and run-time access control, and customer controlled data encryption. For each approach, this paper thoroughly analyzes its technical principles, key technologies, state of the art, as well as practical possibilities in the real world. At last, this paper points out the future research directions and key technologies against insider threats in the cloud.

Original languageEnglish
Pages (from-to)296-316
Number of pages21
JournalJisuanji Xuebao/Chinese Journal of Computers
Volume40
Issue number2
DOIs
StatePublished - 1 Feb 2017
Externally publishedYes

Keywords

  • Behavior analysis
  • Cloud computing
  • Data encryption
  • Internal threats
  • Permissions control

Fingerprint

Dive into the research topics of 'Survey on Insider Threats to Cloud Computing'. Together they form a unique fingerprint.

Cite this