서브메뉴
검색
Faasten: An Architecture and Implementation for Securing Cloud Applications
Faasten: An Architecture and Implementation for Securing Cloud Applications
상세정보
- 자료유형
- 학위논문 서양
- 최종처리일시
- 20250211152840
- ISBN
- 9798346759294
- DDC
- 004
- 저자명
- Tan, Yue.
- 서명/저자
- Faasten: An Architecture and Implementation for Securing Cloud Applications
- 발행사항
- [Sl] : Princeton University, 2024
- 발행사항
- Ann Arbor : ProQuest Dissertations & Theses, 2024
- 형태사항
- 95 p
- 주기사항
- Source: Dissertations Abstracts International, Volume: 86-06, Section: B.
- 주기사항
- Advisor: Levy, Amit.
- 학위논문주기
- Thesis (Ph.D.)--Princeton University, 2024.
- 초록/해제
- 요약Modern web applications have evolved into intricate networks of micro-applications, posing challenges in securing user data and preserving privacy. In the current approach, developers scatter authorization checks throughout the code, relying on them to secure all data paths that may emerge during runtime, often without real guarantees. This method imposes a heavy burden on developers to write secure code and poses significant risks on privacy, especially when development priorities focus on application features and user experience.To address these issues, this dissertation advocates for a different architecture where no code is trusted to be secure, and the underlying system enforces end-to-end, high-level policies for individual data objects.We designed Faasten, an architecture and implementation for securing cloud-based web applications. Faasten includes a decentralized information flow control (DIFC) model and a Function-as-a-Service-inspired system interface that implements this model. The design offers developers built-in noninterference and only requires them to configure policies for individual data objects and privileges for individual cloud functions. For privilege configuration, the design also facilitates easy privilege separation and promotes the principle of least privilege. Faasten is language-agnostic and can secure legacy code, such as image processing libraries commonly used in web applications. We provide an informal proof demonstrating that the interface ensures noninterference and showcase the benefits of Faasten through three representative cloud applications. Additionally, we show that Faasten introduces negligible latencies in doing information flow control and minimal policy storage costs.
- 일반주제명
- Computer science
- 일반주제명
- Computer engineering
- 키워드
- Cloud computing
- 키워드
- Systems security
- 기타저자
- Princeton University Computer Science
- 기본자료저록
- Dissertations Abstracts International. 86-06B.
- 전자적 위치 및 접속
- 로그인 후 원문을 볼 수 있습니다.
MARC
008250123s2024 us c eng d■001000017164180
■00520250211152840
■006m o d
■007cr#unu||||||||
■020 ▼a9798346759294
■035 ▼a(MiAaPQ)AAI31562626
■040 ▼aMiAaPQ▼cMiAaPQ
■0820 ▼a004
■1001 ▼aTan, Yue.
■24510▼aFaasten: An Architecture and Implementation for Securing Cloud Applications
■260 ▼a[Sl]▼bPrinceton University▼c2024
■260 1▼aAnn Arbor▼bProQuest Dissertations & Theses▼c2024
■300 ▼a95 p
■500 ▼aSource: Dissertations Abstracts International, Volume: 86-06, Section: B.
■500 ▼aAdvisor: Levy, Amit.
■5021 ▼aThesis (Ph.D.)--Princeton University, 2024.
■520 ▼aModern web applications have evolved into intricate networks of micro-applications, posing challenges in securing user data and preserving privacy. In the current approach, developers scatter authorization checks throughout the code, relying on them to secure all data paths that may emerge during runtime, often without real guarantees. This method imposes a heavy burden on developers to write secure code and poses significant risks on privacy, especially when development priorities focus on application features and user experience.To address these issues, this dissertation advocates for a different architecture where no code is trusted to be secure, and the underlying system enforces end-to-end, high-level policies for individual data objects.We designed Faasten, an architecture and implementation for securing cloud-based web applications. Faasten includes a decentralized information flow control (DIFC) model and a Function-as-a-Service-inspired system interface that implements this model. The design offers developers built-in noninterference and only requires them to configure policies for individual data objects and privileges for individual cloud functions. For privilege configuration, the design also facilitates easy privilege separation and promotes the principle of least privilege. Faasten is language-agnostic and can secure legacy code, such as image processing libraries commonly used in web applications. We provide an informal proof demonstrating that the interface ensures noninterference and showcase the benefits of Faasten through three representative cloud applications. Additionally, we show that Faasten introduces negligible latencies in doing information flow control and minimal policy storage costs.
■590 ▼aSchool code: 0181.
■650 4▼aComputer science
■650 4▼aComputer engineering
■653 ▼aCloud computing
■653 ▼aInformation flow control
■653 ▼aSystems security
■690 ▼a0984
■690 ▼a0464
■71020▼aPrinceton University▼bComputer Science.
■7730 ▼tDissertations Abstracts International▼g86-06B.
■790 ▼a0181
■791 ▼aPh.D.
■792 ▼a2024
■793 ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17164180▼nKERIS▼z이 자료의 원문은 한국교육학술정보원에서 제공합니다.


