{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T08:54:49Z","timestamp":1777971289219,"version":"3.51.4"},"reference-count":48,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2020,6,9]],"date-time":"2020-06-09T00:00:00Z","timestamp":1591660800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,6,9]],"date-time":"2020-06-09T00:00:00Z","timestamp":1591660800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/100009790","name":"University at Albany","doi-asserted-by":"publisher","award":["Startup"],"award-info":[{"award-number":["Startup"]}],"id":[{"id":"10.13039\/100009790","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["CCF Trans. Netw."],"published-print":{"date-parts":[[2020,10]]},"DOI":"10.1007\/s42045-020-00028-9","type":"journal-article","created":{"date-parts":[[2020,6,9]],"date-time":"2020-06-09T10:03:14Z","timestamp":1591696994000},"page":"112-127","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["A multi-level proactive security auditing framework for clouds through automated dependency building"],"prefix":"10.1007","volume":"3","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6501-4214","authenticated-orcid":false,"given":"Suryadipta","family":"Majumdar","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,6,9]]},"reference":[{"key":"28_CR1","doi-asserted-by":"crossref","unstructured":"Aikat, J., Akella, A., Chase, J.S., Juels, A., Reiter, M., Ristenpart, T., Sekar, V., Swift, M.: Rethinking security in the era of cloud computing. IEEE Secur. Privacy 15(3), (2017)","DOI":"10.1109\/MSP.2017.80"},{"key":"28_CR2","unstructured":"Amazon. Amazon virtual private cloud. Available at: https:\/\/aws.amazon.com\/vpc. Accessed 14 Feb 2018"},{"key":"28_CR3","unstructured":"Bellare, M., Yee, B.: Forward integrity for secure audit logs. Technical report, Citeseer (1997)"},{"key":"28_CR4","doi-asserted-by":"crossref","unstructured":"Beschastnikh, I., Brun, Y., Schneider, S., Sloan, M., Ernst, M.\u00a0D.: Leveraging existing instrumentation to automatically infer invariant-constrained models. In: Proceedings of the 19th ACM SIGSOFT symposium and the 13th European conference on Foundations of software engineering. ACM, (2011)","DOI":"10.1145\/2025113.2025151"},{"key":"28_CR5","doi-asserted-by":"crossref","unstructured":"Bleikertz, S., Vogel, C., Gro\u00df, T., M\u00f6dersheim, S.: Proactive security analysis of changes in virtualized infrastructures. In: ACSAC, (2015)","DOI":"10.1145\/2818000.2818034"},{"key":"28_CR6","doi-asserted-by":"crossref","unstructured":"Doelitzscher, F., Fischer, C., Moskal, D., Reich, C., Knahl, M., Clarke, N.: Validating cloud infrastructure changes by cloud audits. In: Services. IEEE, (2012)","DOI":"10.1109\/SERVICES.2012.12"},{"key":"28_CR7","unstructured":"Elasticsearch: Logstash. Available at: https:\/\/www.elastic.co\/products\/logstash. Accessed on: 14 Feb (2018)"},{"key":"28_CR8","unstructured":"Google: Google cloud platform. Available at: https:\/\/cloud.google.com. Accessed on: 14 Feb 2018"},{"key":"28_CR9","doi-asserted-by":"crossref","unstructured":"H\u00e4m\u00e4l\u00e4inen, W., Nyk\u00e4nen, M.: Efficient discovery of statistically significant association rules. In: ICDM, pp. 203\u2013212. IEEE, (2008)","DOI":"10.1109\/ICDM.2008.144"},{"key":"28_CR10","doi-asserted-by":"crossref","unstructured":"Hong, S., Xu, L., Wang, H., Gu, G.: Poisoning network visibility in software-defined networks: New attacks and countermeasures. In: Proceedings of 2015 Annual Network and Distributed System Security Symposium (NDSS\u201915), (2015)","DOI":"10.14722\/ndss.2015.23283"},{"issue":"9","key":"28_CR11","doi-asserted-by":"publisher","first-page":"1737","DOI":"10.1109\/TPAMI.2014.2385695","volume":"37","author":"J Kwon","year":"2015","unstructured":"Kwon, J., Lee, K.M.: A unified framework for event summarization and rare event detection from multiple views. IEEE Trans. Pattern Anal. Mach. Intell. 37(9), 1737\u20131750 (2015)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"28_CR12","doi-asserted-by":"crossref","unstructured":"Li, M., Zang, W., Bai, K., Yu, M., Liu, P.: Mycloud: supporting user-configured privacy protection in cloud computing. In: ACSAC, pp 59\u201368. ACM, (2013)","DOI":"10.1145\/2523649.2523680"},{"key":"28_CR13","unstructured":"Lopes, N.\u00a0P., Bj\u00f8rner, N., Godefroid, P., Jayaraman, K., Varghese, G.: Checking beliefs in dynamic networks. In: 12th USENIX Symposium on Networked Systems Design and Implementation (NSDI\u201915), pp 499\u2013512, (2015)"},{"key":"28_CR14","doi-asserted-by":"crossref","unstructured":"Luo, Y., Luo, W., Puyang, T., Shen, Q., Ruan, A., Wu, Z.: OpenStack security modules: a least-invasive access control framework for the cloud. In: CLOUD, (2016)","DOI":"10.1109\/CLOUD.2016.0017"},{"issue":"1","key":"28_CR15","first-page":"1","volume":"22","author":"T Madi","year":"2018","unstructured":"Madi, T., Jarraya, Y., Alimohammadifar, A., Majumdar, S., Wang, Y., Pourzandi, M., Wang, L., Debbabi, M.: ISOTOP: auditing virtual networks isolation across cloud layers in OpenStack. ACM Trans. Privacy Secur. 22(1), 1 (2018)","journal-title":"ACM Trans. Privacy Secur."},{"key":"28_CR16","doi-asserted-by":"crossref","unstructured":"Madi, T., Majumdar, S., Wang, Y., Jarraya, Y., Pourzandi, M., Wang, L.: Auditing security compliance of the virtualized infrastructure in the cloud: application to openstack. In: CODASPY, pp. 195\u2013206. ACM, (2016)","DOI":"10.1145\/2857705.2857721"},{"key":"28_CR17","doi-asserted-by":"crossref","unstructured":"Majumdar, S., Jarraya, Y., Madi, T., Alimohammadifar, A., Pourzandi, M., Wang, L., Debbabi, M.: Proactive verification of security compliance for clouds through pre-computation: application to OpenStack. In: ESORICS, (2016)","DOI":"10.1007\/978-3-319-45744-4_3"},{"key":"28_CR18","doi-asserted-by":"crossref","unstructured":"Majumdar, S., Jarraya, Y., Oqaily, M., Alimohammadifar, A., Pourzandi, M., Wang, L., Debbabi, M.: LeaPS: Learning-based proactive security auditing for clouds. In: ESORICS, (2017)","DOI":"10.1007\/978-3-319-66399-9_15"},{"key":"28_CR19","doi-asserted-by":"crossref","unstructured":"Majumdar, S., Madi, T., Wang, Y., Jarraya, Y., Pourzandi, M., Wang, L., Debbabi, M.: Security compliance auditing of identity and access management in the cloud: application to OpenStack. In: CloudCom, pp. 58\u201365. IEEE, (2015)","DOI":"10.1109\/CloudCom.2015.80"},{"issue":"5","key":"28_CR20","doi-asserted-by":"publisher","first-page":"1185","DOI":"10.1109\/TIFS.2017.2779444","volume":"13","author":"S Majumdar","year":"2018","unstructured":"Majumdar, S., Madi, T., Wang, Y., Jarraya, Y., Pourzandi, M., Wang, L., Debbabi, M.: User-level runtime security auditing for the cloud. IEEE Trans. Inf. Forensics Secur. 13(5), 1185\u20131199 (2018)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"2","key":"28_CR21","doi-asserted-by":"publisher","first-page":"165","DOI":"10.3233\/JCS-181137","volume":"27","author":"S Majumdar","year":"2019","unstructured":"Majumdar, S., Tabiban, A., Jarraya, Y., Oqaily, M., Alimohammadifar, A., Pourzandi, M., Wang, L., Debbabi, M.: Learning probabilistic dependencies among events for proactive security auditing in clouds. J. Comput. Secur. 27(2), 165\u2013202 (2019)","journal-title":"J. Comput. Secur."},{"key":"28_CR22","doi-asserted-by":"crossref","unstructured":"Majumdar, S., Tabiban, A., Mohammady, M., Oqaily, A., Jarraya, Y., Pourzandi, M., Wang, L., Debbabi, M.: Multi-level proactive security auditing for cloud. In: IEEE Conference on Dependable and Secure Computing (DSC), (2019)","DOI":"10.1007\/978-3-030-23128-6"},{"key":"28_CR23","doi-asserted-by":"crossref","unstructured":"Majumdar, S., Tabiban, A., Mohammady, M., Oqaily, A., Jarraya, Y., Pourzandi, M., Wang, L., Debbabi, M.: Proactivizer: Transforming existing verification tools into efficient solutions for runtime security enforcement. In: ESORICS, (2019)","DOI":"10.1007\/978-3-030-29962-0_12"},{"key":"28_CR24","unstructured":"Microsoft: Microsoft Azure virtual network. Available at: https:\/\/azure.microsoft.com. Accessed on: 14 Feb 2018"},{"key":"28_CR25","unstructured":"Murphy, K.: A brief introduction to graphical models and bayesian networks. (1998)"},{"key":"28_CR26","unstructured":"OpenStack: Neutron security groups bypass through invalid cidr, 2015. Available at: https:\/\/security.openstack.org\/ossa\/OSSA-2014-014.html. Accessed on: 14 Feb 2018"},{"key":"28_CR27","unstructured":"OpenStack: Nova network security group changes are not applied to running instances, 2015. Available at: https:\/\/security.openstack.org\/ossa\/OSSA-2015-021.html, Accessed on: 14 Feb 2018"},{"key":"28_CR28","unstructured":"OpenStack: OpenStack Congress, 2015. Available at: https:\/\/wiki.openstack.org\/wiki\/Congress, Accessed on: 14 Feb 2018"},{"key":"28_CR29","unstructured":"OpenStack: OpenStack open source cloud computing software, 2015. Available at: http:\/\/www.openstack.org, Accessed on: 14 Feb 2018"},{"key":"28_CR30","unstructured":"OpenStack: OpenStack user survey, 2016. Available at: https:\/\/www.openstack.org\/assets\/survey\/October2016SurveyReport.pdf. Accessed on: 14 Feb 14 2018"},{"key":"28_CR31","unstructured":"OpenStack: OpenStack logging, 2018. Available at: https:\/\/docs.openstack.org\/operations-guide\/ops-logging.html. Accessed on: 07 April 2020"},{"key":"28_CR32","doi-asserted-by":"crossref","unstructured":"Peng, W., Perng, C., Li, T., Wang, H.: Event summarization for system management. In: Proceedings of the 13th ACM SIGKDD international conference on Knowledge discovery and data mining. ACM, (2007)","DOI":"10.1145\/1281192.1281305"},{"key":"28_CR33","unstructured":"Priestley, M.\u00a0B.: Spectral analysis and time series. (1981)"},{"key":"28_CR34","doi-asserted-by":"crossref","unstructured":"Ristenpart, T., Tromer, E., Shacham, H., Savage, S.: Hey, you, get off of my cloud: exploring information leakage in third-party compute clouds. In: CCS. ACM, (2009)","DOI":"10.1145\/1653662.1653687"},{"key":"28_CR35","doi-asserted-by":"crossref","unstructured":"Schear, N., Cable\u00a0II, P.\u00a0T., Moyer, T.\u00a0M., Richard, B., Rudd, R.: Bootstrapping and maintaining trust in the cloud. In: ACSAC, (2016)","DOI":"10.1145\/2991079.2991104"},{"key":"28_CR36","doi-asserted-by":"crossref","unstructured":"Skowyra, R., Xu, L., Gu, G., Hobson, T., Dedhia, V., Landry, J., Okhravi, H.: Effective topology tampering attacks and defenses in software-defined networks. In: Proceedings of the 48th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN\u201915), (2018)","DOI":"10.1109\/DSN.2018.00047"},{"key":"28_CR37","doi-asserted-by":"crossref","unstructured":"Tabiban, A., Majumdar, S., Wang, L., Debbabi, M.: Permon: An openstack middleware for runtime security policy enforcement in clouds. In: SPC, (2018)","DOI":"10.1109\/CNS.2018.8433180"},{"key":"28_CR38","unstructured":"Tamura, N., Banbara, M.: Sugar: A CSP to SAT translator based on order encoding. In: Proceedings of the Second International CSP Solver Competition, pp. 65\u201369 (2008)"},{"key":"28_CR39","doi-asserted-by":"crossref","unstructured":"Ullah, K.\u00a0W., Ahmed, A.\u00a0S., Ylitalo, J.: Towards building an automated security compliance tool for the cloud. In: TrustCom, pp. 1587\u20131593. IEEE, (2013)","DOI":"10.1109\/TrustCom.2013.195"},{"key":"28_CR40","doi-asserted-by":"crossref","unstructured":"Varadarajan, V., Kooburat, T., Farley, B., Ristenpart, T., Swift, M.\u00a0M.: Resource-freeing attacks: improve your cloud performance (at your neighbor\u2019s expense). In: CCS. ACM, (2012)","DOI":"10.1145\/2382196.2382228"},{"key":"28_CR41","unstructured":"VMware: VMware vCloud Director. Available at: https:\/\/www.vmware.com. Accessed on: 14 Feb 2018"},{"issue":"2","key":"28_CR42","doi-asserted-by":"publisher","first-page":"362","DOI":"10.1109\/TC.2011.245","volume":"62","author":"C Wang","year":"2013","unstructured":"Wang, C., Chow, S.S., Wang, Q., Ren, K., Lou, W.: Privacy-preserving public auditing for secure cloud storage. IEEE Trans. Comput. 62(2), 362\u2013375 (2013)","journal-title":"IEEE Trans. Comput."},{"issue":"4","key":"28_CR43","doi-asserted-by":"publisher","first-page":"940","DOI":"10.1109\/TIFS.2016.2646913","volume":"12","author":"Y Wang","year":"2017","unstructured":"Wang, Y., Wu, Q., Qin, B., Shi, W., Deng, R.H., Hu, J.: Identity-based data outsourcing with comprehensive auditing in clouds. IEEE Trans. Inf. Forensics Secur. 12(4), 940\u2013952 (2017)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"28_CR44","unstructured":"WSGI: Middleware and libraries for WSGI, 2016. Available at: http:\/\/wsgi.readthedocs.io\/en\/latest\/libraries.html. Accessed on: 15 Feb 2018"},{"key":"28_CR45","unstructured":"Xu, Z., Wang, H., Wu, Z.: A measurement study on co-residence threat inside the cloud. In: USENIX Security (2015)"},{"key":"28_CR46","doi-asserted-by":"crossref","unstructured":"Yau, S.\u00a0S., Buduru, A.\u00a0B., Nagaraja, V.: Protecting critical cloud infrastructures with predictive capability. In: CLOUD, pp. 1119\u20131124. IEEE, (2015)","DOI":"10.1109\/CLOUD.2015.165"},{"key":"28_CR47","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Juels, A., Reiter, M.\u00a0K., Ristenpart, T.: Cross-VM side channels and their use to extract private keys. In: CCS. ACM, (2012)","DOI":"10.1145\/2382196.2382230"},{"key":"28_CR48","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Juels, A., Reiter, M.\u00a0K., Ristenpart, T.: Cross-tenant side-channel attacks in PaaS clouds. In: CCS. ACM, (2014)","DOI":"10.1145\/2660267.2660356"}],"container-title":["CCF Transactions on Networking"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42045-020-00028-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s42045-020-00028-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42045-020-00028-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,6,8]],"date-time":"2021-06-08T23:20:20Z","timestamp":1623194420000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s42045-020-00028-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,6,9]]},"references-count":48,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2020,10]]}},"alternative-id":["28"],"URL":"https:\/\/doi.org\/10.1007\/s42045-020-00028-9","relation":{},"ISSN":["2520-8462","2520-8470"],"issn-type":[{"value":"2520-8462","type":"print"},{"value":"2520-8470","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,6,9]]},"assertion":[{"value":"4 December 2019","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 May 2020","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 June 2020","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}