SlideShare a Scribd company logo
www.paasword.eu
No More Dark Clouds With PaaSword – An
Innovative Security By Design Framework
Project Overview
Cloud Paradigm Shift
The cloud paradigm has definitely prevailed
Most application are delivered following the SaaS model
Many developers rely on PaaS offerings for scalablity
Nearly all underlying resources (DBs, Queues etc) are outsourced
at the IaaS level
Attack vectors have increased
‘Raw data’ are the modern hacker’s holy grail
The responsibility for the protection of data has shifted to the
developer
PaaSword04/11/2016 2
60% of attacks target the
database
PaaSword04/11/2016 3
Data leaks
PaaSword 4
Motivation – Security as an Enterprise
Requirement
Enterprises identify security concerns and data privacy as the most
significant barriers of Cloud adoption;
In addition:
Compliance (e.g., legal, regulatory, industry-standard compliance)
Cultural resistance
Encryption and key management as top priority requirements [3] & [4]
PaaSword 5
[3] P. Institute, “2015 Global Encryption & Key,” Thales, 2015.
[4] CipherCloud, “Global cloud data security report - The
authority on how to protect data in the cloud,” CipherCloud, 2015.
How shall we lower the barriers?
Security concerns
Protect confidential information
Control access
Trust cloud provider
Secure Cloud Applications
Data privacy
Secure storage
Encryption
Trustable Key Management
Control Access to data
PaaSword 6
PaaSword
Problem Areas Targeted
Insufficient security and trust of cloud infrastructures
and services
Cloud application developers have difficulties specifying
appropriate level of security
Appropriate context-aware access control mechanisms
for cloud applications
Ensure protection, privacy and integrity of data stored
in the cloud
Prove applicability, usability, effectiveness and value of
secure cloud platforms
PaaSword 7
PaaSword Platform
PaaSword04/11/2016 8
PaaSword Features
A security-by-design framework which
will allow developers to engineer secure
applications
Leverage the security and trust of data
that reside on outsourced infrastructure
Facilitate context-aware access to
encrypted and (even) physically
distributed datasets stored in the cloud
Prove applicability, usability,
effectiveness and value of our framework
in real-life Cloud infrastructures, services
and applications
9
PaaS Provider
PaaSword API
DB with
Indexers on encrypted data
Queries using Searchable
Trusted IaaS Provider
Adversary
User
Developer
Publishes Application
Encryption Scheme
using PaaSword API
encrypted data
PaaSword
Major Assets developed so far

A JAVA annotation library that can be used during development in
order to annotate database models (using JPA)
These annotations are translated during runtime to privacy constraints that
drive the fragmentation of the database
A virtual-database proxy that is able to handle any SQL query by
translating it in the proper format based on the fragmentation
scheme
An XACML-compliant authorization engine that is able to perform
reasoning prior to attribute-evaluation
An integrated IDE environment where developers can submit and
control their PaaSword-enabled applications
PaaSword 10
Integration of Eclipse CHE IDE
PaaSword 11
Native Integration with
OpenStack
PaaSword 12
Asset: Virtual Database Architecture
PaaSword 13
Data Index2Index1
SQL
SQLDatabase
Proxy
(trusted)
SQL
Cloud
(untrusted)
User / Application
Data
(not encrypted)
Data (encrypted)
Model-driven Expression editing
PaaSword 14
Interested in
 ?
Getting access to early results?
Shaping and expanding PaaSword?
Networking with leading companies & research
institutes?
Collaborating with us and the PaaSword Community?
Join the Cloud Security Industrial Focus Group!
Register at:
https://www.paasword.eu/register/
19PaaSword
PaaSword 20
Join our Industrial Focus Group Today!
Visit us:
www.paasword.euAcknowledgements:
This project has received funding from the
European Union’s Horizon 2020 research and
innovation programme under grant
agreement No 644814.

More Related Content

PDF
No More Dark Clouds With PaaSword - An Innovative Security By Design Framework
PDF
PaaSword - No More Dark Clouds with PaaSword
PDF
History of Privacera
PPTX
Azure security and Compliance
PDF
Empower your security practitioners with the Elastic Stack
PPTX
Is Pharma Ready for the Cloud?
PDF
Search for All with Elastic Enterprise Search
PDF
Cloudera GoDataFest Deploying Cloudera in the Cloud
No More Dark Clouds With PaaSword - An Innovative Security By Design Framework
PaaSword - No More Dark Clouds with PaaSword
History of Privacera
Azure security and Compliance
Empower your security practitioners with the Elastic Stack
Is Pharma Ready for the Cloud?
Search for All with Elastic Enterprise Search
Cloudera GoDataFest Deploying Cloudera in the Cloud

What's hot (20)

PPT
Cloud Security Alliance's GRC Stack Overview
PDF
ASPIRE by Edge Solutions Media Technologies
PPTX
Enterprise Hadoop in the Cloud. In Minutes. | How to Run Cloudera Enterprise ...
PDF
Azure 101: Shared responsibility in the Azure Cloud
PPTX
Azure Security Center- Zero to Hero
PPTX
Document fingerprinting in Microsoft 365 Compliance
PDF
Cloudera GoDataFest Security and Governance
PDF
What is your PaaS
PPTX
Cloud Security, Risk and Compliance on AWS
PDF
Getting Started with Azure Security Center
PPTX
Securing Your CI Pipeline with HashiCorp Vault - P2
PPTX
ECS19 - Nicki Borell - Microsoft Cybersecurity Reference Architecture
PDF
ECS19 - Bram De Jager - Design a secure collaboration solution with Azure In...
PDF
O365Con18 - Classify, Label and Protect your Data with Azure Information Prot...
PDF
1. aws security and compliance wwps pre-day sao paolo - markry
PPTX
Azure Sentinel Jan 2021 overview deck
PPTX
Self-service Big Data Analytics on Microsoft Azure
PPTX
Apache Knox Gateway "Single Sign On" expands the reach of the Enterprise Users
PPTX
Standing Up an Effective Enterprise Data Hub -- Technology and Beyond
PPTX
Shawn Harris - CCSP SAH v2
Cloud Security Alliance's GRC Stack Overview
ASPIRE by Edge Solutions Media Technologies
Enterprise Hadoop in the Cloud. In Minutes. | How to Run Cloudera Enterprise ...
Azure 101: Shared responsibility in the Azure Cloud
Azure Security Center- Zero to Hero
Document fingerprinting in Microsoft 365 Compliance
Cloudera GoDataFest Security and Governance
What is your PaaS
Cloud Security, Risk and Compliance on AWS
Getting Started with Azure Security Center
Securing Your CI Pipeline with HashiCorp Vault - P2
ECS19 - Nicki Borell - Microsoft Cybersecurity Reference Architecture
ECS19 - Bram De Jager - Design a secure collaboration solution with Azure In...
O365Con18 - Classify, Label and Protect your Data with Azure Information Prot...
1. aws security and compliance wwps pre-day sao paolo - markry
Azure Sentinel Jan 2021 overview deck
Self-service Big Data Analytics on Microsoft Azure
Apache Knox Gateway "Single Sign On" expands the reach of the Enterprise Users
Standing Up an Effective Enterprise Data Hub -- Technology and Beyond
Shawn Harris - CCSP SAH v2
Ad

Viewers also liked (20)

DOC
Mohamed Ali CV
PDF
PURE Executive Brochure
PDF
GA3030_2_jc252233_Stationery
PDF
Peer Acceptance and the Emotional Well-Being of Disabled
PDF
Basel III SA credit-risk comments 1_032015
PDF
HomeClass KEUKENS en BADKAMERS
PPTX
Interview powerpoint
PPTX
Analysis of a professional front cover
PPTX
Mengelola Sumber Daya Manusia
PPTX
Production of front cover image
PDF
Daten unter Kontrolle
PPTX
DMSSO 2016 - The Real State of SEO in 2016 and Beyond @nagyseo
DOCX
Brian's CV (2) (1)
PDF
The Forest Lake Times _ ..
PPTX
ENGL 396: Ethics of Style
DOC
Dissertation master document
PPTX
1. Membuat Blog Dengan Wordpress
PPTX
Production of double page spread image
PPTX
Australia Sopt Assessment
PPTX
STRATOS ICU Presentation CHR La Citadelle LiĂšge 280315 short version
Mohamed Ali CV
PURE Executive Brochure
GA3030_2_jc252233_Stationery
Peer Acceptance and the Emotional Well-Being of Disabled
Basel III SA credit-risk comments 1_032015
HomeClass KEUKENS en BADKAMERS
Interview powerpoint
Analysis of a professional front cover
Mengelola Sumber Daya Manusia
Production of front cover image
Daten unter Kontrolle
DMSSO 2016 - The Real State of SEO in 2016 and Beyond @nagyseo
Brian's CV (2) (1)
The Forest Lake Times _ ..
ENGL 396: Ethics of Style
Dissertation master document
1. Membuat Blog Dengan Wordpress
Production of double page spread image
Australia Sopt Assessment
STRATOS ICU Presentation CHR La Citadelle LiĂšge 280315 short version
Ad

Similar to PaaSword Presentation - Project Overview (20)

PDF
PaaSword's main idea, technical architecture and scientific challenges
PDF
No More Dark Clouds: A Privacy Preserving Framework for the Cloud
PDF
PaaSword-Business Cases
PDF
A Data Privacy and Security by Design Platform‐as‐a‐Service Framework
PDF
PaaSword - Technology Baseline
PDF
PaaSword: A Holistic Data Privacy and Security by Design Framework for Cloud ...
PPT
PaaSword: A Holistic Data Privacy and Security by Design Framework for Cloud ...
PDF
A New Approach for Securely Sharing Data between Cloud Users with Dual Keys
 
PDF
Implementing Iris in the Railway Control Office Application for Secure Saas i...
PDF
A Novel Computing Paradigm for Data Protection in Cloud Computing
 
PDF
Paper id 27201448
 
PDF
Critical_Review_of_Openstack_Security_Is.pdf
PDF
A proficient 5 c approach to boost the security in the saas model's technical...
 
PDF
Security of Data in Cloud Environment Using DPaaS
 
PDF
wp-security-dbsec-cloud-3225125
PDF
Cloud Computing: Provide privacy and Security in Database-as-a-Service
PDF
1376842823 2982373
PDF
1376842823 2982373
PDF
Practical advice for cloud data protection ulf mattsson - bright talk webin...
PDF
SaaS Platform Securing
PaaSword's main idea, technical architecture and scientific challenges
No More Dark Clouds: A Privacy Preserving Framework for the Cloud
PaaSword-Business Cases
A Data Privacy and Security by Design Platform‐as‐a‐Service Framework
PaaSword - Technology Baseline
PaaSword: A Holistic Data Privacy and Security by Design Framework for Cloud ...
PaaSword: A Holistic Data Privacy and Security by Design Framework for Cloud ...
A New Approach for Securely Sharing Data between Cloud Users with Dual Keys
 
Implementing Iris in the Railway Control Office Application for Secure Saas i...
A Novel Computing Paradigm for Data Protection in Cloud Computing
 
Paper id 27201448
 
Critical_Review_of_Openstack_Security_Is.pdf
A proficient 5 c approach to boost the security in the saas model's technical...
 
Security of Data in Cloud Environment Using DPaaS
 
wp-security-dbsec-cloud-3225125
Cloud Computing: Provide privacy and Security in Database-as-a-Service
1376842823 2982373
1376842823 2982373
Practical advice for cloud data protection ulf mattsson - bright talk webin...
SaaS Platform Securing

Recently uploaded (20)

PDF
top salesforce developer skills in 2025.pdf
PDF
Adobe Illustrator 28.6 Crack My Vision of Vector Design
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PDF
System and Network Administration Chapter 2
PPTX
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
PPTX
Introduction to Artificial Intelligence
PDF
Understanding Forklifts - TECH EHS Solution
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 41
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PPT
Introduction Database Management System for Course Database
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PPTX
ai tools demonstartion for schools and inter college
PDF
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
PPTX
CHAPTER 12 - CYBER SECURITY AND FUTURE SKILLS (1) (1).pptx
PDF
Navsoft: AI-Powered Business Solutions & Custom Software Development
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PDF
PTS Company Brochure 2025 (1).pdf.......
PPTX
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
PPTX
history of c programming in notes for students .pptx
PDF
medical staffing services at VALiNTRY
top salesforce developer skills in 2025.pdf
Adobe Illustrator 28.6 Crack My Vision of Vector Design
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
System and Network Administration Chapter 2
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
Introduction to Artificial Intelligence
Understanding Forklifts - TECH EHS Solution
Internet Downloader Manager (IDM) Crack 6.42 Build 41
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
Introduction Database Management System for Course Database
Odoo Companies in India – Driving Business Transformation.pdf
ai tools demonstartion for schools and inter college
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
CHAPTER 12 - CYBER SECURITY AND FUTURE SKILLS (1) (1).pptx
Navsoft: AI-Powered Business Solutions & Custom Software Development
Design an Analysis of Algorithms I-SECS-1021-03
PTS Company Brochure 2025 (1).pdf.......
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
history of c programming in notes for students .pptx
medical staffing services at VALiNTRY

PaaSword Presentation - Project Overview

  • 1. www.paasword.eu No More Dark Clouds With PaaSword – An Innovative Security By Design Framework Project Overview
  • 2. Cloud Paradigm Shift The cloud paradigm has definitely prevailed Most application are delivered following the SaaS model Many developers rely on PaaS offerings for scalablity Nearly all underlying resources (DBs, Queues etc) are outsourced at the IaaS level Attack vectors have increased ‘Raw data’ are the modern hacker’s holy grail The responsibility for the protection of data has shifted to the developer PaaSword04/11/2016 2
  • 3. 60% of attacks target the database PaaSword04/11/2016 3
  • 5. Motivation – Security as an Enterprise Requirement Enterprises identify security concerns and data privacy as the most significant barriers of Cloud adoption; In addition: Compliance (e.g., legal, regulatory, industry-standard compliance) Cultural resistance Encryption and key management as top priority requirements [3] & [4] PaaSword 5 [3] P. Institute, “2015 Global Encryption & Key,” Thales, 2015. [4] CipherCloud, “Global cloud data security report - The authority on how to protect data in the cloud,” CipherCloud, 2015.
  • 6. How shall we lower the barriers? Security concerns Protect confidential information Control access Trust cloud provider Secure Cloud Applications Data privacy Secure storage Encryption Trustable Key Management Control Access to data PaaSword 6 PaaSword
  • 7. Problem Areas Targeted Insufficient security and trust of cloud infrastructures and services Cloud application developers have difficulties specifying appropriate level of security Appropriate context-aware access control mechanisms for cloud applications Ensure protection, privacy and integrity of data stored in the cloud Prove applicability, usability, effectiveness and value of secure cloud platforms PaaSword 7
  • 9. PaaSword Features A security-by-design framework which will allow developers to engineer secure applications Leverage the security and trust of data that reside on outsourced infrastructure Facilitate context-aware access to encrypted and (even) physically distributed datasets stored in the cloud Prove applicability, usability, effectiveness and value of our framework in real-life Cloud infrastructures, services and applications 9 PaaS Provider PaaSword API DB with Indexers on encrypted data Queries using Searchable Trusted IaaS Provider Adversary User Developer Publishes Application Encryption Scheme using PaaSword API encrypted data PaaSword
  • 10. Major Assets developed so far
 A JAVA annotation library that can be used during development in order to annotate database models (using JPA) These annotations are translated during runtime to privacy constraints that drive the fragmentation of the database A virtual-database proxy that is able to handle any SQL query by translating it in the proper format based on the fragmentation scheme An XACML-compliant authorization engine that is able to perform reasoning prior to attribute-evaluation An integrated IDE environment where developers can submit and control their PaaSword-enabled applications PaaSword 10
  • 11. Integration of Eclipse CHE IDE PaaSword 11
  • 13. Asset: Virtual Database Architecture PaaSword 13 Data Index2Index1 SQL SQLDatabase Proxy (trusted) SQL Cloud (untrusted) User / Application Data (not encrypted) Data (encrypted)
  • 15. Interested in
 ? Getting access to early results? Shaping and expanding PaaSword? Networking with leading companies & research institutes? Collaborating with us and the PaaSword Community? Join the Cloud Security Industrial Focus Group! Register at: https://www.paasword.eu/register/ 19PaaSword
  • 16. PaaSword 20 Join our Industrial Focus Group Today! Visit us: www.paasword.euAcknowledgements: This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 644814.