{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,10]],"date-time":"2026-01-10T03:30:09Z","timestamp":1768015809277,"version":"3.49.0"},"publisher-location":"Cham","reference-count":33,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319457437","type":"print"},{"value":"9783319457444","type":"electronic"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-45744-4_3","type":"book-chapter","created":{"date-parts":[[2016,9,14]],"date-time":"2016-09-14T04:54:30Z","timestamp":1473828870000},"page":"47-66","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":20,"title":["Proactive Verification of Security Compliance for Clouds Through Pre-computation: Application to OpenStack"],"prefix":"10.1007","author":[{"given":"Suryadipta","family":"Majumdar","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yosr","family":"Jarraya","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Taous","family":"Madi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Amir","family":"Alimohammadifar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Makan","family":"Pourzandi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lingyu","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mourad","family":"Debbabi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,9,15]]},"reference":[{"key":"3_CR1","unstructured":"Bellare, M., Yee, B.: Forward integrity for secure audit logs. Technical report, Citeseer (1997)"},{"key":"3_CR2","doi-asserted-by":"crossref","unstructured":"Bleikertz, S., Vogel, C., Gro\u00df, T.: Cloud radar: near real-time detection of security failures in dynamic virtualized infrastructures. In: Proceedings of the 30th Annual Computer Security Applications Conference, ACSAC 2014 (2014)","DOI":"10.1145\/2664243.2664274"},{"key":"3_CR3","doi-asserted-by":"crossref","unstructured":"Bleikertz, S., Vogel, C., Gro\u00df, T., M\u00f6dersheim, S.: Proactive security analysis of changes in virtualized infrastructure. In: Proceedings of the 31st Annual Computer Security Applications Conference, ACSAC 2015 (2015)","DOI":"10.1145\/2818000.2818034"},{"key":"3_CR4","unstructured":"Cloud Auditing Data Federation: pyCADF: A Python-based CADF library (2015). https:\/\/pypi.python.org\/pypi\/pycadf"},{"key":"3_CR5","unstructured":"Cloud Security Alliance: Security guidance for critical areas of focus in cloud computing v3.0 (2011)"},{"key":"3_CR6","unstructured":"Cloud Security Alliance: Cloud control matrix CCM v3.0.1. https:\/\/cloudsecurityalliance.org\/research\/ccm\/"},{"key":"3_CR7","unstructured":"Cloud Security Alliance: CSA STAR program and open certification framework in 2016 and beyond (2016). https:\/\/downloads.cloudsecurityalliance.org\/star\/csa-star-program-cert-prep.pdf"},{"key":"3_CR8","unstructured":"Data Center Knowledge: Survey one-third of cloud users\u2019 clouds are private, heavily OpenStack (2015). http:\/\/www.datacenterknowledge.com\/archives\/2015\/01\/30\/survey-half-of-private-clouds-are-openstack-clouds"},{"key":"3_CR9","doi-asserted-by":"crossref","unstructured":"Dolzhenko, E., Ligatti, J., Reddy, S.: Modeling runtime enforcement with mandatory results automata. Int. J. Inf. Secur. (2014)","DOI":"10.1007\/s10207-014-0239-8"},{"key":"3_CR10","doi-asserted-by":"crossref","unstructured":"Foley, S.N., Neville, U.: A firewall algebra for openstack. In: IEEE Conference on Communications and Network Security (CNS) (2015)","DOI":"10.1109\/CNS.2015.7346867"},{"key":"3_CR11","doi-asserted-by":"crossref","unstructured":"Ibrahim, A.S., Hamlyn-Harris, J., Grundy, J., Almorsy, M.: CloudSec: a security monitoring appliance for virtual machines in the IaaS cloud model. In: 5th International Conference on Network and System Security (NSS) (2011)","DOI":"10.1109\/ICNSS.2011.6059967"},{"key":"3_CR12","unstructured":"ISO Std IEC. ISO 27017: Information technology - Security techniques - Code of practice for information security controls based on ISO\/IEC 27002 for cloud services (DRAFT) (2012). http:\/\/www.iso27001security.com\/html\/27017.html"},{"key":"3_CR13","unstructured":"Kazemian, P., Chang, M., Zeng, H., Varghese, G., McKeown, N., Whyte, S.: Real time network policy checking using header space analysis. In: Proceedings of the 10th USENIX Symposium on Networked Systems Design and Implementation (NSDI 2013) (2013)"},{"key":"3_CR14","doi-asserted-by":"crossref","unstructured":"Khurshid, A., Zou, X., Zhou, W., Caesar, M., Godfrey, P.B.: VeriFlow: verifying network-wide invariants in real time. In: Proceedings of the 10th USENIX Symposium on Networked Systems Design and Implementation (NSDI 2013) (2013)","DOI":"10.1145\/2342441.2342452"},{"key":"3_CR15","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1145\/1455526.1455532","volume":"12","author":"J Ligatti","year":"2009","unstructured":"Ligatti, J., Bauer, L., Walker, D.: Run-time enforcement of nonsafety policies. ACM Trans Inf. Syst. Secur. (TISSEC) 12, 19 (2009)","journal-title":"ACM Trans Inf. Syst. Secur. (TISSEC)"},{"key":"3_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1007\/978-3-642-15497-3_6","volume-title":"Computer Security \u2013 ESORICS 2010","author":"J Ligatti","year":"2010","unstructured":"Ligatti, J., Reddy, S.: A theory of runtime enforcement, with results. In: Gritzalis, D., Preneel, B., Theoharidou, M. (eds.) ESORICS 2010. LNCS, vol. 6345, pp. 87\u2013100. Springer, Heidelberg (2010)"},{"key":"3_CR17","doi-asserted-by":"crossref","unstructured":"Madi, T., Majumdar, S., Wang, Y., Jarraya, Y., Pourzandi, M., Wang, L.: Auditing security compliance of the virtualized infrastructure in the cloud: application to OpenStack. In: Proceedings of the Sixth ACM on Conference on Data and Application Security and Privacy (CODASPY) (2016)","DOI":"10.1145\/2857705.2857721"},{"key":"3_CR18","doi-asserted-by":"crossref","unstructured":"Majumdar, S., Madi, T., Wang, Y., Jarraya, Y., Pourzandi, M., Wang, L., Debbabi, M.: Security compliance auditing of identity and access management in the cloud: application to OpenStack. In: IEEE 7th International Conference on Cloud Computing Technology and Science (CloudCom) (2015)","DOI":"10.1109\/CloudCom.2015.80"},{"key":"3_CR19","unstructured":"Narain, S.: Network configuration management via model finding. In: Proceedings of the 19th Conference on Large Installation System Administration Conference, LISA 2005 (2005)"},{"key":"3_CR20","unstructured":"OpenStack: Neutron firewall rules bypass through port update. https:\/\/security.openstack.org\/ossa\/OSSA-2015-018.html"},{"key":"3_CR21","unstructured":"OpenStack: OpenStack Congress. https:\/\/wiki.openstack.org\/wiki\/Congress"},{"key":"3_CR22","unstructured":"OpenStack: OpenStack open source cloud computing software. http:\/\/www.openstack.org"},{"key":"3_CR23","unstructured":"OpenStack: OpenStack user survey. https:\/\/www.openstack.org\/assets\/survey\/Public-User-Survey-Report.pdf"},{"key":"3_CR24","unstructured":"OpenStack: OpenStack audit middleware. http:\/\/docs.openstack.org\/developer\/keystonemiddleware\/audit.html"},{"key":"3_CR25","unstructured":"OpenStack: OpenStack command list. http:\/\/docs.openstack.org\/developer\/python-openstackclient\/command-list.html"},{"key":"3_CR26","doi-asserted-by":"crossref","unstructured":"Payne, B.D., Carbone, M., Sharif, M., Lee, W.: Lares: an architecture for secure active monitoring using virtualization. In: IEEE Symposium on Security and Privacy (SP 2008) (2008)","DOI":"10.1109\/SP.2008.24"},{"key":"3_CR27","unstructured":"Petcu, D., Craciun, C.: Towards a security SLA-based cloud monitoring service. In: Proceedings of the 4th International Conference on Cloud Computing and Services Science (2014)"},{"key":"3_CR28","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1109\/2.485845","volume":"29","author":"R Sandhu","year":"1996","unstructured":"Sandhu, R., Coyne, E.J., Feinstein, H.L., Youman, C.E.: Role-based access control models. IEEE Comput. 29, 38\u201347 (1996)","journal-title":"IEEE Comput."},{"key":"3_CR29","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1145\/353323.353382","volume":"3","author":"FB Schneider","year":"2000","unstructured":"Schneider, F.B.: Enforceable security policies. ACM Trans. Inf. Syst. Secur. (TISSEC) 3, 30\u201350 (2000)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"3_CR30","unstructured":"Solanas, M., Hernandez-Castro, J., Dutta, D.: Detecting fraudulent activity in a cloud using privacy-friendly data aggregates. Technical report, arXiv preprint (2014)"},{"key":"3_CR31","unstructured":"Tamura, N., Banbara, M.: Sugar: a CSP to SAT translator based on order encoding. In: Proceedings of the Second International CSP Solver Competition (2008)"},{"key":"3_CR32","series-title":"Lecture Notes in Computer Science","first-page":"54","volume-title":"Network and System Security","author":"B Tang","year":"2014","unstructured":"Tang, B., Sandhu, R.: Extending OpenStack access control with domain trust. In: Au, M.H., Carminati, B., Kuo, C.-C.J. (eds.) NSS 2014. LNCS, vol. 8792, pp. 54\u201369. Springer, Heidelberg (2014)"},{"key":"3_CR33","doi-asserted-by":"crossref","unstructured":"Zhang, T., Lee, R.B.: Cloudmonatt: an architecture for security health monitoring and attestation of virtual machines in cloud computing. In: ACM\/IEEE 42nd Annual International Symposium on Computer Architecture (ISCA) (2015)","DOI":"10.1145\/2749469.2750422"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2016"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-45744-4_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,8]],"date-time":"2022-07-08T11:14:08Z","timestamp":1657278848000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-45744-4_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319457437","9783319457444"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-45744-4_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016]]},"assertion":[{"value":"15 September 2016","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Heraklion","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Greece","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2016","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 September 2016","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 September 2016","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2016","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}