Run-Time Monitoring and Hash-Based Verification for Secure Client Machine States in Untrusted Cloud Infrastructures
DOI:
https://doi.org/10.62643/Abstract
Cloud computing is increasingly adopted across critical sectors such as healthcare, banking, and social media due to its scalability, cost-effectiveness, and high-performance storage and computation capabilities. However, the delegation of data and computation to third-party cloud infrastructures introduces substantial security and privacy risks, including data manipulation and unauthorized access by internal or external entities. A Zero-Trust run-time framework is introduced to address these threats by continuously monitoring and verifying the client machine’s state. This framework, termed Trusted Public Cloud (TPC), ensures integrity by integrating a kernel-level monitoring module, trust agent, Software Trusted Platform Module (SWTPM), and a verification cluster. It validates client-side changes using cryptographic hashing and real-time verification logic to detect anomalies and unauthorized modifications. The system supports dynamic verification policies using 'Include' and 'Exclude' strategies to optimize computation. Additionally, a log-based activity monitoring extension is incorporated to identify and block malicious users based on login behavior patterns. The framework is locally implemented to emulate cloud behavior and tested with simulated virtual machines, offering effective machine state tracking and real-time alerts against security breaches.
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.













