Home
Scholarly Works
Formal verification of secure information flow in...
Journal article

Formal verification of secure information flow in cloud computing

Abstract

Federated cloud systems increase the reliability and reduce the cost of computational support to an organisation. However, the resulting combination of secure private clouds and less secure public clouds impacts on the overall security of the system as applications need to be located within different clouds. In this paper, the entities of a federated cloud system as well as the clouds are assigned security levels of a given security lattice. Then a dynamic flow sensitive security model for a federated cloud system is introduced within which the Bell–LaPadula rules and cloud security rule can be captured. The rest of the paper demonstrates how Petri nets and the associated verification techniques could be used to analyse the security of information flow in federated cloud systems.

Authors

Zeng W; Koutny M; Watson P; Germanos V

Journal

Journal of Information Security and Applications, Vol. 27, , pp. 103–116

Publisher

Elsevier

Publication Date

April 1, 2016

DOI

10.1016/j.jisa.2016.03.002

ISSN

2214-2134

Contact the Experts team