Thursday, 15 January 2015

A STOCHASTIC MODEL TO IMPROVING PERFORMANCE AND QOS IN IAAS CLOUD SYSTEMS



S.Pavithra, K.Savima

1PG Student STET Women’s college, mannargudi.
2Professor of IT department, STET Women’s college, mannargudi.


Cloud data center management is a key problem due to the numerous and heterogeneous strategies that can be applied, ranging from the VM placement to the federation with other clouds. Performance evaluation of Cloud Computing infrastructures is required to predict and quantify the cost-benefit of a strategy portfolio and the corresponding Quality of Service (QoS) experienced by users. Such analyses are not feasible by simulation or on-the-field experimentation, due to the great number of parameters that have to be investigated. In this paper, we present an analytical model, based on Stochastic Reward Nets (SRNs), that is both scalable to model systems composed of thousands of resources and flexible to represent different policies and cloud-specific strategies. Several performance metrics are defined and evaluated to analyze the behavior of a Cloud data center: utilization, availability, waiting time, and responsiveness. A resiliency analysis is also provided to take into account load bursts. Finally, a general approach is presented that, starting from the concept of system capacity, can help system managers to opportunely set the data center parameters under different working conditions. Cloud data center management is a key problem due to the numerous and heterogeneous strategies that can be applied, ranging from the VM placement to the federation with other clouds. Performance evaluation of Cloud Computing infrastructures is required to predict and quantify the cost-benefit of a strategy portfolio and the corresponding Quality of Service (QoS) experienced by users. Analyses are not feasible by simulation or on-the-field experimentation, due to the great number of parameters that have to be investigated. An analytical model, based on Stochastic Reward Nets (SRNs), that is both scalable to model systems composed of thousands of resources and flexible to represent different policies and cloud-specific strategies. Several performance metrics are defined and evaluated to analyze the behavior of a Cloud data center: utilization, availability, waiting time, and responsiveness. A resiliency analysis is also provided to take into account load bursts.  A general approach is presented that, starting from the concept of system capacity to help system managers opportunely set the data center parameters under different working conditions.
Share:

EXPRESSIVE, EFFICIENT AND REVOCABLE DATA ACCESS SECURITY CONTROL FOR MULTI-AUTHORITY CLOUD STORAGE



S.Monika, K.Savima
1PG Student STET Women’s college, mannargudi
2Professor of IT department, STET Women’s college, mannargudi

Privacy, trust and access control are some of the security concepts in the Cloud systems. Access control is of vital importance in a Cloud environment since it is concerned with allowing a user to access a number of Cloud resources. The data access control is an effective way to ensure the data security in the cloud. Due to data outsourcing and untrusted cloud servers, the data access control becomes a challenging issue in cloud storage systems. It is important to protect the data and privacy of users. Cipher text-Policy Attribute based Encryption (CP-ABE) is regarded as one of the most suitable technologies for data access control in cloud storage, because it gives data owners more direct control on access policies. It is difficult to directly apply existing CP-ABE schemes to data access control for cloud storage systems because of the attribute revocation problem.  Design an expressive, efficient and revocable data access control scheme for multi-authority cloud storage systems, where there The Authority in CP-ABE scheme is responsible for attribute management and key are multiple authorities co-exist and each authority is able to issue attributes independently. The Authority in CP-ABE scheme is responsible for attribute management and key distribution. Propose a revocable multi-authority CP-ABE scheme, and apply it as the underlying techniques to design the data access control scheme. Attribute revocation method can efficiently achieve both forward security and backward security. The analysis and simulation results show that the proposed data access control scheme is secure in the random model and is more efficient.
Share:

SECURING SERVER BROKER LESS PUBLISH/SUBSCRIBE USING ID BASED ENCRYPTION




E.Deepika,V.Geetha

1PG Student STET Women’s college, mannargudi
2Professor of CS department, STET Women’s college, mannargudi


The publish/subscribe (pub/sub) communication paradigm has gained high popularity because of its inherent decoupling of publishers from subscribers inters of time, space, and synchronization. Publishers inject information into the pub/sub system, and subscribers specify the events of interest by means of subscriptions. Authentication of publishers and subscribers is difficult to achieve due to the loose coupling of publishers and subscribers. Likewise, confidentiality of events and subscriptions conflicts with content-based routing. This paper presents a novel approach to provide confidentiality and authentication in a broker-less content-based publish/subscribe system. The authentication of publishers and subscribers as well as confidentiality of events is ensured, by adapting the pairing-based cryptography mechanisms, to the needs of a publish/subscribe system. Furthermore, an algorithm to cluster subscribers according to their subscriptions preserves a weak notion of subscription confidentiality. In addition to our previous work this paper contributes use of searchable encryption to enable efficient routing of encrypted events, multi credential routing a new event dissemination strategy to strengthen the weak subscription confidentiality, and  thorough analysis of different attacks on subscription confidentiality. The overall approach provides fine-grained key management and the cost for encryption, decryption, and routing is in the order of subscribed attributes. Moreover, the evaluations show that providing security is affordable throughput of the proposed cryptographic primitives, and  delays incurred during the construction of the publish/subscribe overlay and the event dissemination.
Share:

A STUDY ON RELIABLE SERVICE THAT ENABLING SECURING SERVICE ORIENTED MOBILE SOCIAL NETWORK



P.Abirami, R.BhuvanaPriya

1PG Student STET Women’s college, mannargudi
2Professor of CS department, STET Women’s college, mannargudi

A Trustworthy Service Evaluation (TSE) system to enable users to share service reviews in service-oriented mobile social networks (S-MSNs). Each service provider independently maintains a TSE for itself, which collects and stores users’ reviews about its services without requiring any third trusted authority. The service reviews can then be made available to interested users in making wise service selection decisions. Identify three unique service review attacks, i.e., link ability, rejection, and modification attacks, and develop sophisticated security mechanisms for the TSE to deal with these attacks.  The basic TSE (bTSE) enables users to distributed and cooperatively submit their reviews in an integrated chain form by using hierarchical and aggregate signature techniques. It restricts the service providers to reject, modify, or delete the reviews. Thus, the integrity and authenticity of reviews are improved. Further, extend the bTSE to a Sybil-resisted TSE (SrTSE) to enable the detection of two typical Sybil attacks.In the SrTSE, if a user generates multiple reviews toward a vendor in a predefined time slot with different pseudonyms, the real identity of that user will be revealed. Through security Analysis and numerical results, that the bTSE and the SrTSE effectively resist the Service review attacks and the SrTSE additionally detect the Sybil attacks in an efficient manner. Through performance evaluation, the bTSE achieves better performance in terms of submission rate and delay than a service review system that does not adopt user cooperation
Share:

ANONYMOUS AUTHENTICATION OF CLOUDS DATA WITH DA CONTROL USING ATTRIBUTE BASED ENCRYPTION

S.Abirami, J.Sangeetha
1PG Student STET Women’s college, Mannargudi.
2Professor of CS department, STET Women’s college, Mannargudi.

 Cloud computing is a rising technology delivers a lot of new challenges for data security and access control when clients outsource sensitive data for offering on cloud servers, which computing standard  assets of the computing framework are given as a service over the Internet. As guaranteeing as it may be, this standard additionally are not inside the same trusted dominion as data possessors. In any case, in completing thus, these results unavoidably present a substantial processing overhead on the data possessor for key distribution and data administration when fine-grained data access control is in demand, and subsequently don't scale well. The issue of at the same time accomplishing fine-grainedness, scalability, and data confidentiality of access control really still remains uncertain. This paper addresses this open issue by, on one hand, characterizing and implementing access policies based on data qualities, and, then again, permitting the data owner to representative the majority of the calculation undertakings included in fine-grained data access control to un-trusted cloud servers without unveiling the underlying data substance. We accomplish this goal by exploiting and combining techniques of decentralized key policy Attribute Based Encryption (KP-ABE). Extensive investigation shows that the proposed approach is highly efficient and secure. Cloud computing is typically defined as a type of computing that relies on sharing computing resources rather than having local servers or personal devices to handle applications .Cloud Computing is the internet-based storage for files, applications, and infrastructure. Cloud computing involves deploying groups of remote servers and software networks that allow centralized data storage and online access to computer services or resources. Centralized computing is computing done at a central location, using terminals that are attached to a central computer. The computer itself may control all the peripherals directly or they may be attached via a terminal server. Information security is a critical issue in cloud computing environments, so the nature of cloud computing raises serious issues regarding user authentication, information integrity and data confidentiality. Propose a new decentralized access control scheme is  for secure data storage in clouds that supports anonymous authentication. In the proposed scheme, the cloud verifies the authenticity of the series without knowing the user's identity before storing data. Our scheme also has the added feature of access control in which only valid users are able to decrypt the stored information. The scheme prevents replay attacks and supports creation, modification, and reading data stored in the cloud, also address user revocation. Moreover, authentication and access control scheme is decentralized and robust, unlike other access control schemes designed for clouds which are centralized. The communication, computation, and storage overheads
Share: