Security operation center implementation on OpenStack

Tala Tafazzoli, Hossein Gharaee Garakani · 2016

Information security management is a complicated task in cloud environment. Cloud service layers and multi-tenant architecture have created a complicated environment for developing and managing a monitoring and incident response environment in organizations. The main goal of this paper is to receive and analyze events from OpenStack environment. Events and system logs are received from OpenStack environment. The organization SOC must be customized to receive and detect cloud specific attacks. In this paper, we customize SOC for OpenStack environment to detect cloud specific attacks. The customized SOC receives and normalizes OpenStack alerts. We have developed new correlation rules and response scenarios for these alerts. We have presented evaluation results of customized SOC development in OpenStack. The customized SOC can detect OpenStack and hypervisor based attacks.

Read the paper · More papers on PaperTik