Zhi Guan

Work place: School of EECS, Peking University, Beijing, China

E-mail: guanzhi@infosec.pku.edu.cn

Website:

Research Interests: Application Security, Hardware Security, Information Security, Network Security

Biography

Zhi Guan received his B.S. degree from Dalian University of Technology and Ph.D. degree from the Peking University, in 2002 and 2009 respectively. He is currently an assistant professor at Peking University. His research interests include applied cryptography, security and privacy of RFID.

Author Articles
A Novel Framework to Carry Out Cloud Penetration Test

By Jianbin Hu Yonggang Wang Cong Tang Zhi Guan Fengxian Ren Zhong Chen

DOI: https://doi.org/10.5815/ijcnis.2011.03.01, Pub. Date: 8 Apr. 2011

In current cloud services, users put their data and resources into the cloud so as to enjoy the on-demand high quality applications and services. Different from the conventional services, users in cloud services lose control of their data which is instead manipulated by the large-scale cloud. Therefore, cloud service providers (CSP) guarantee that the cloud which they provide is of high confidence in accuracy and integrity. Traditional penetration test is carried out manually and has low efficiency. In this paper, we propose FPTC, a novel framework of penetration test in cloud environment. In FPTC, there are managers, executors and toolkits. FPTC managers guide FPTC executors to gather information from the cloud environment, generate appropriate testing scenarios, run matched tools in the toolkit and collect test results to do evaluation. The capacity and quality of the toolkit is a key issue in FPTC. We develop a prototype in which FPTC is implemented and the experimental results show that FPTC is helpful to automatically carry out penetration test in cloud environment.

[...] Read more.
Other Articles