SA-UBA: Automatically Privileged User Behavior Auditing for Cloud Platforms with Securely Accounts Management
Cloud platforms allow administrators or management applications with privileged accounts to remotely perform privileged operations for specific tasks, such as deleting virtual hosts. When privileged accounts are leaked and conduct dangerous privileged operations, severe security problems will appear...
Main Authors: | , , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
MDPI AG
2022-08-01
|
Series: | Applied Sciences |
Subjects: | |
Online Access: | https://www.mdpi.com/2076-3417/12/17/8763 |
_version_ | 1827667020096733184 |
---|---|
author | Hezhong Pan Peiyi Han Xiayu Xiang Shaoming Duan Chuanyi Liu |
author_facet | Hezhong Pan Peiyi Han Xiayu Xiang Shaoming Duan Chuanyi Liu |
author_sort | Hezhong Pan |
collection | DOAJ |
description | Cloud platforms allow administrators or management applications with privileged accounts to remotely perform privileged operations for specific tasks, such as deleting virtual hosts. When privileged accounts are leaked and conduct dangerous privileged operations, severe security problems will appear on cloud platforms. To solve these problems, researchers focus on auditing privileged users’ behaviors. However, it is difficult to automatically audit fine-grained privileged behaviors for graphical operating systems. Moreover, it is hard to prevent users from bypassing the audit system or to prevent hackers from attacking audit system. In this paper, we propose a Secure and Automatic Behavior Audit system named SA-UBA. It provides advanced deep learning models to automatically achieve fine-grained user behavior audits for graphical operating systems. Furthermore, it adopts cryptography-based account storage and sharing methods to securely manage privileged accounts. In particular, privileged accounts cannot be leaked even if SA-UBA is compromised by attackers. We built a threat model of a cloud platform to evaluate the security of the SA-UBA and conduct extensive experiments with SA-UBA in real scenarios. The results show SA-UBA introduces a small overhead on securely managing privileged accounts and accurately recognizes fine-grained user behaviors. |
first_indexed | 2024-03-10T03:00:49Z |
format | Article |
id | doaj.art-6d9a36c78454463aa6c877787e19e011 |
institution | Directory Open Access Journal |
issn | 2076-3417 |
language | English |
last_indexed | 2024-03-10T03:00:49Z |
publishDate | 2022-08-01 |
publisher | MDPI AG |
record_format | Article |
series | Applied Sciences |
spelling | doaj.art-6d9a36c78454463aa6c877787e19e0112023-11-23T12:46:28ZengMDPI AGApplied Sciences2076-34172022-08-011217876310.3390/app12178763SA-UBA: Automatically Privileged User Behavior Auditing for Cloud Platforms with Securely Accounts ManagementHezhong Pan0Peiyi Han1Xiayu Xiang2Shaoming Duan3Chuanyi Liu4School of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing 100876, ChinaSchool of Computer Science and Technology, Harbin Institute of Technology (Shenzhen), Shenzhen 518055, ChinaPeng Cheng Laboratory, Shenzhen 518055, ChinaSchool of Computer Science and Technology, Harbin Institute of Technology (Shenzhen), Shenzhen 518055, ChinaSchool of Computer Science and Technology, Harbin Institute of Technology (Shenzhen), Shenzhen 518055, ChinaCloud platforms allow administrators or management applications with privileged accounts to remotely perform privileged operations for specific tasks, such as deleting virtual hosts. When privileged accounts are leaked and conduct dangerous privileged operations, severe security problems will appear on cloud platforms. To solve these problems, researchers focus on auditing privileged users’ behaviors. However, it is difficult to automatically audit fine-grained privileged behaviors for graphical operating systems. Moreover, it is hard to prevent users from bypassing the audit system or to prevent hackers from attacking audit system. In this paper, we propose a Secure and Automatic Behavior Audit system named SA-UBA. It provides advanced deep learning models to automatically achieve fine-grained user behavior audits for graphical operating systems. Furthermore, it adopts cryptography-based account storage and sharing methods to securely manage privileged accounts. In particular, privileged accounts cannot be leaked even if SA-UBA is compromised by attackers. We built a threat model of a cloud platform to evaluate the security of the SA-UBA and conduct extensive experiments with SA-UBA in real scenarios. The results show SA-UBA introduces a small overhead on securely managing privileged accounts and accurately recognizes fine-grained user behaviors.https://www.mdpi.com/2076-3417/12/17/8763user behavior auditprivileged account managementcloud security |
spellingShingle | Hezhong Pan Peiyi Han Xiayu Xiang Shaoming Duan Chuanyi Liu SA-UBA: Automatically Privileged User Behavior Auditing for Cloud Platforms with Securely Accounts Management Applied Sciences user behavior audit privileged account management cloud security |
title | SA-UBA: Automatically Privileged User Behavior Auditing for Cloud Platforms with Securely Accounts Management |
title_full | SA-UBA: Automatically Privileged User Behavior Auditing for Cloud Platforms with Securely Accounts Management |
title_fullStr | SA-UBA: Automatically Privileged User Behavior Auditing for Cloud Platforms with Securely Accounts Management |
title_full_unstemmed | SA-UBA: Automatically Privileged User Behavior Auditing for Cloud Platforms with Securely Accounts Management |
title_short | SA-UBA: Automatically Privileged User Behavior Auditing for Cloud Platforms with Securely Accounts Management |
title_sort | sa uba automatically privileged user behavior auditing for cloud platforms with securely accounts management |
topic | user behavior audit privileged account management cloud security |
url | https://www.mdpi.com/2076-3417/12/17/8763 |
work_keys_str_mv | AT hezhongpan saubaautomaticallyprivilegeduserbehaviorauditingforcloudplatformswithsecurelyaccountsmanagement AT peiyihan saubaautomaticallyprivilegeduserbehaviorauditingforcloudplatformswithsecurelyaccountsmanagement AT xiayuxiang saubaautomaticallyprivilegeduserbehaviorauditingforcloudplatformswithsecurelyaccountsmanagement AT shaomingduan saubaautomaticallyprivilegeduserbehaviorauditingforcloudplatformswithsecurelyaccountsmanagement AT chuanyiliu saubaautomaticallyprivilegeduserbehaviorauditingforcloudplatformswithsecurelyaccountsmanagement |