5
1 Towards a Discipline of Mission-Aware Cloud Computing (A Position Paper) Ravi Sandhu Executive Director and Endowed Professor October 2010 [email protected], www.profsandhu.com, www.ics.utsa.edu Joint work with Raj Boppana, Ram Krishnan, Jeff Reich, Todd Wolff and Josh Zachary © Ravi Sandhu World-Leading Research with Real-World Impact! Institute for Cyber Security

1 Towards a Discipline of Mission-Aware Cloud Computing (A Position Paper) Ravi Sandhu Executive Director and Endowed Professor October 2010 [email protected],

Embed Size (px)

Citation preview

Page 1: 1 Towards a Discipline of Mission-Aware Cloud Computing (A Position Paper) Ravi Sandhu Executive Director and Endowed Professor October 2010 ravi.sandhu@utsa.edu,

1

Towards a Discipline ofMission-Aware Cloud Computing

(A Position Paper)

Ravi SandhuExecutive Director and Endowed Professor

October 2010

[email protected], www.profsandhu.com, www.ics.utsa.edu

Joint work with Raj Boppana, Ram Krishnan,Jeff Reich, Todd Wolff and Josh Zachary

© Ravi Sandhu World-Leading Research with Real-World Impact!

Institute for Cyber Security

Page 2: 1 Towards a Discipline of Mission-Aware Cloud Computing (A Position Paper) Ravi Sandhu Executive Director and Endowed Professor October 2010 ravi.sandhu@utsa.edu,

The NIST terminology IaaS, PaaS, SaaS Public, Private, Hybrid, Community Elasticity, on demand, etc

Basic premise The cloud is here to stay We are only in the initial stages

Layman’s terms Cloud computing moves computing, data, information

resources into the network (the “cloud”) and Make these instantly and seamlessly accessible from

multiple devices (PCs, smart phones and tablets)

© Ravi Sandhu 2World-Leading Research with Real-World Impact!

Cloud Computing

Page 3: 1 Towards a Discipline of Mission-Aware Cloud Computing (A Position Paper) Ravi Sandhu Executive Director and Endowed Professor October 2010 ravi.sandhu@utsa.edu,

Attractions: Economics Productivity

Concerns: Dependability Security

Guess who wins?!

© Ravi Sandhu 3World-Leading Research with Real-World Impact!

Cloud Computing

Page 4: 1 Towards a Discipline of Mission-Aware Cloud Computing (A Position Paper) Ravi Sandhu Executive Director and Endowed Professor October 2010 ravi.sandhu@utsa.edu,

Cyber security has evolved Computer security Computer security + Communications security

Consider ACM Computer and Communications Security (CCS) Conference founded 1993

Information security Information assurance Mission assurance

The cloud, or any other cyber infrastructure, by itself cannot guarantee mission assurance.

Cyber security then becomes a piece of the larger goal of mission assurance.

© Ravi Sandhu 4World-Leading Research with Real-World Impact!

Cyber Security

Page 5: 1 Towards a Discipline of Mission-Aware Cloud Computing (A Position Paper) Ravi Sandhu Executive Director and Endowed Professor October 2010 ravi.sandhu@utsa.edu,

Research challenges include Realistic-scale experimental instrumented research cloud

infrastructure Enhancing strength of VM separation Predictability of computation/communication performance Identification and mitigation of new attack paths and threats Models and languages for specifying cyber requirements of

a missionAutomated adjustment of mission cyber support based on

cyber/external situational awareness Rapid reconfiguration in response to major mode changes Protecting/controlling information on the client

© Ravi Sandhu 5World-Leading Research with Real-World Impact!

Mission Aware Cloud