Resilient Cloud Services (RCS)
ABSTRACT
Cloud Computing will be widely adopted and effectively used only if the security issues in cloud computing are addressed. Securing cloud applications and services is a challenging research problem because it involves many interdependent tasks including vulnerability scanning, application layer firewalls, configuration management, alert monitoring and analysis, source code analysis, and user identity management. Furthermore, it is widely accepted that cyber attacks cannot be prevented and they do exist. Cyber Resilient techniques are the most promising techniques to secure the cloud.
In this presentation, Resilient Cloud Application Services using Moving Target Defense Techniques will be presented. By continuously changing the execution environment during runtime, this makes it extremely difficult for an attacker to successfully attack the system. In this work, three applications were used to evaluate the performance and overhead of the presented approach. Those applications were implemented on an IBM Bladecenter Private Cloud that consists of 198 cores, where each core can run several virtual machines. The results show that the presented approach makes the environment resilient for attacks, with around only 7% overhead time.