SA-UBA: Automatically Privileged User Behavior Auditing for Cloud Platforms with Securely Accounts Management

Cloud platforms allow administrators or management applications with privileged accounts to remotely perform privileged operations for specific tasks, such as deleting virtual hosts. When privileged accounts are leaked and conduct dangerous privileged operations, severe security problems will appear...

Full description

Bibliographic Details
Main Authors: Hezhong Pan, Peiyi Han, Xiayu Xiang, Shaoming Duan, Chuanyi Liu
Format: Article
Language:English
Published: MDPI AG 2022-08-01
Series:Applied Sciences
Subjects:
Online Access:https://www.mdpi.com/2076-3417/12/17/8763
_version_ 1827667020096733184
author Hezhong Pan
Peiyi Han
Xiayu Xiang
Shaoming Duan
Chuanyi Liu
author_facet Hezhong Pan
Peiyi Han
Xiayu Xiang
Shaoming Duan
Chuanyi Liu
author_sort Hezhong Pan
collection DOAJ
description Cloud platforms allow administrators or management applications with privileged accounts to remotely perform privileged operations for specific tasks, such as deleting virtual hosts. When privileged accounts are leaked and conduct dangerous privileged operations, severe security problems will appear on cloud platforms. To solve these problems, researchers focus on auditing privileged users’ behaviors. However, it is difficult to automatically audit fine-grained privileged behaviors for graphical operating systems. Moreover, it is hard to prevent users from bypassing the audit system or to prevent hackers from attacking audit system. In this paper, we propose a Secure and Automatic Behavior Audit system named SA-UBA. It provides advanced deep learning models to automatically achieve fine-grained user behavior audits for graphical operating systems. Furthermore, it adopts cryptography-based account storage and sharing methods to securely manage privileged accounts. In particular, privileged accounts cannot be leaked even if SA-UBA is compromised by attackers. We built a threat model of a cloud platform to evaluate the security of the SA-UBA and conduct extensive experiments with SA-UBA in real scenarios. The results show SA-UBA introduces a small overhead on securely managing privileged accounts and accurately recognizes fine-grained user behaviors.
first_indexed 2024-03-10T03:00:49Z
format Article
id doaj.art-6d9a36c78454463aa6c877787e19e011
institution Directory Open Access Journal
issn 2076-3417
language English
last_indexed 2024-03-10T03:00:49Z
publishDate 2022-08-01
publisher MDPI AG
record_format Article
series Applied Sciences
spelling doaj.art-6d9a36c78454463aa6c877787e19e0112023-11-23T12:46:28ZengMDPI AGApplied Sciences2076-34172022-08-011217876310.3390/app12178763SA-UBA: Automatically Privileged User Behavior Auditing for Cloud Platforms with Securely Accounts ManagementHezhong Pan0Peiyi Han1Xiayu Xiang2Shaoming Duan3Chuanyi Liu4School of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing 100876, ChinaSchool of Computer Science and Technology, Harbin Institute of Technology (Shenzhen), Shenzhen 518055, ChinaPeng Cheng Laboratory, Shenzhen 518055, ChinaSchool of Computer Science and Technology, Harbin Institute of Technology (Shenzhen), Shenzhen 518055, ChinaSchool of Computer Science and Technology, Harbin Institute of Technology (Shenzhen), Shenzhen 518055, ChinaCloud platforms allow administrators or management applications with privileged accounts to remotely perform privileged operations for specific tasks, such as deleting virtual hosts. When privileged accounts are leaked and conduct dangerous privileged operations, severe security problems will appear on cloud platforms. To solve these problems, researchers focus on auditing privileged users’ behaviors. However, it is difficult to automatically audit fine-grained privileged behaviors for graphical operating systems. Moreover, it is hard to prevent users from bypassing the audit system or to prevent hackers from attacking audit system. In this paper, we propose a Secure and Automatic Behavior Audit system named SA-UBA. It provides advanced deep learning models to automatically achieve fine-grained user behavior audits for graphical operating systems. Furthermore, it adopts cryptography-based account storage and sharing methods to securely manage privileged accounts. In particular, privileged accounts cannot be leaked even if SA-UBA is compromised by attackers. We built a threat model of a cloud platform to evaluate the security of the SA-UBA and conduct extensive experiments with SA-UBA in real scenarios. The results show SA-UBA introduces a small overhead on securely managing privileged accounts and accurately recognizes fine-grained user behaviors.https://www.mdpi.com/2076-3417/12/17/8763user behavior auditprivileged account managementcloud security
spellingShingle Hezhong Pan
Peiyi Han
Xiayu Xiang
Shaoming Duan
Chuanyi Liu
SA-UBA: Automatically Privileged User Behavior Auditing for Cloud Platforms with Securely Accounts Management
Applied Sciences
user behavior audit
privileged account management
cloud security
title SA-UBA: Automatically Privileged User Behavior Auditing for Cloud Platforms with Securely Accounts Management
title_full SA-UBA: Automatically Privileged User Behavior Auditing for Cloud Platforms with Securely Accounts Management
title_fullStr SA-UBA: Automatically Privileged User Behavior Auditing for Cloud Platforms with Securely Accounts Management
title_full_unstemmed SA-UBA: Automatically Privileged User Behavior Auditing for Cloud Platforms with Securely Accounts Management
title_short SA-UBA: Automatically Privileged User Behavior Auditing for Cloud Platforms with Securely Accounts Management
title_sort sa uba automatically privileged user behavior auditing for cloud platforms with securely accounts management
topic user behavior audit
privileged account management
cloud security
url https://www.mdpi.com/2076-3417/12/17/8763
work_keys_str_mv AT hezhongpan saubaautomaticallyprivilegeduserbehaviorauditingforcloudplatformswithsecurelyaccountsmanagement
AT peiyihan saubaautomaticallyprivilegeduserbehaviorauditingforcloudplatformswithsecurelyaccountsmanagement
AT xiayuxiang saubaautomaticallyprivilegeduserbehaviorauditingforcloudplatformswithsecurelyaccountsmanagement
AT shaomingduan saubaautomaticallyprivilegeduserbehaviorauditingforcloudplatformswithsecurelyaccountsmanagement
AT chuanyiliu saubaautomaticallyprivilegeduserbehaviorauditingforcloudplatformswithsecurelyaccountsmanagement