2022/05/28 by Francesco Minna, Minna, Francesco, Fabio Massacci +3
Computer Science · Decision Sciences · #Cloud Data Security Solutions #Cryptography and Security (cs.CR) #Data Quality and Management #FOS: Computer and information sciences #Software System Performance and Reliability #cs.CR
paper · pdf · doi:10.48550/arxiv.2205.14498
Conference: The IEEE International Conference on Cloud Computing (CLOUD) 2022
openalex publication_date 2022/05/28 · arxiv created 2022/06/07 · arxiv updated 2022/06/08 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/29
Securing cloud configurations is an elusive task, which is left up to system administrators who have to base their decisions on ``trial and error'' experimentations or by observing good practices (e.g., CIS Benchmarks). We propose a knowledge, AND/OR, graphs approach to model cloud deployment security objects and vulnerabilities. In this way, we can capture relationships between configurations, permissions (e.g., CAP_SYS_ADMIN), and security profiles (e.g., AppArmor and SecComp), as first-class citizens. Such an approach allows us to suggest alternative and safer configurations, support administrators in the study of what-if scenarios, and scale the analysis to large scale deployments. We present an initial validation and illustrate the approach with three real vulnerabilities from known sources.