Skip to main content

Security Vulnerabilities of OpenStack Cloud and Security Assessment Using Different Software Tools

  • Conference paper
  • First Online:
  • 735 Accesses

Part of the book series: Smart Innovation, Systems and Technologies ((SIST,volume 165))

Abstract

New security challenges are raised because of cloud computing when contrasted with customary on-start as a result of its multi-occupant virtual condition on each cloud layer, namely Platform as a Service—PaaS, Infrastructure as a Service—IaaS, or Software as a Service—SaaS. Open clouds are utilizing restrictive cloud programming and security is generally kept up by issuing organizations. Security remains a concern for private clouds. Numerous components influence the cloud mis-configuration and integrity that could emerge on the grounds that security is kept up by an outsider. The target of this investigation is to inspect the territory of OpenStack cloud specifically. This will give a more noteworthy comprehension of in what way cloud computing capacities and any kinds of issues of security emerge in that. The investigation comprises three sections; in the primary section, the foundation of cloud computing and OpenStack is described. In the second section, OpenStack architecture is described. In the third section, known vulnerability exploitation and mitigation strategies are presented along with an assessment of various vulnerabilities in OpenStack is conducted utilizing top security scanners namely Metasploit and OpenVAS in an attempt to finding new vulnerabilities.

This is a preview of subscription content, log in via an institution.

Buying options

Chapter
USD   29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD   169.00
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD   219.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info
Hardcover Book
USD   219.99
Price excludes VAT (USA)
  • Durable hardcover edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Learn about institutional subscriptions

References

  1. Bharati, M., Tamane, S.: Defending against bruteforce attack using open source-SNORT. In: IEEE—International Conference on Inventive Computing and Informatics-2017 (2017). https://ieeexplore.ieee.org/document/8365267/. https://doi.org/10.1109/ICICI.2017.8365267

  2. Bharati, M., Tamane, S.: Intrusion detection systems (IDS) & future challenges in cloud based environment. In: 2017 1st International Conference on Intelligent Systems and Information Management (ICISIM). https://ieeexplore.ieee.org/document/8122180. https://doi.org/10.1109/icisim.2017.8122180

  3. OpenStack Pike: https://releases.openstack.org/pike/

  4. Networking in OpenStack: Panoramic view: https://ilearnstack.com/tag/openstack/

  5. Albaroodi, H., Manickam, S., Singh, P.: Critical review of open-stack security: issues and weeknesses. J. Comput. Sci. 10(1), 23–33 (2014) (National Advanced IPv6 Centre (NAv6), Universiti Sains Malaysia, 11800, Penang, Malaysia)

    Google Scholar 

  6. The Heartbleed bug: http://heartbleed.com/, Openstack—manage IP addresses: https://docs.openstack.org/ocata/user-guide/cli-manage-ipaddresses.html

  7. Installing Metasploit Pro, Ultimate, Express, and Community: https://metasploit.help.rapid7.com/docs

  8. OpenVAS: http://www.openvas.org

  9. Openstack firewalls and default ports: https://docs.openstack.org/newton/config-reference/firewalls-defaultports.html

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Manisha P. Bharati .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2020 Springer Nature Singapore Pte Ltd.

About this paper

Check for updates. Verify currency and authenticity via CrossMark

Cite this paper

Bharati, M.P., Tamane, S.C. (2020). Security Vulnerabilities of OpenStack Cloud and Security Assessment Using Different Software Tools. In: Zhang, YD., Mandal, J., So-In, C., Thakur, N. (eds) Smart Trends in Computing and Communications. Smart Innovation, Systems and Technologies, vol 165. Springer, Singapore. https://doi.org/10.1007/978-981-15-0077-0_22

Download citation

Publish with us

Policies and ethics