CHAPTER 1
INTRODUCTION
A new business model needs support like pay for what they use, IT services through
internet from on-demand services. Cloud provides virtual machines through the internet
facilities. Anything as a Services arena is dynamic in nature which is built through
virtualization provided by hardware, datasets and software networks. Using virtual servers
drifting from desktop services to service oriented arena is the idea.
Maintaining the trust is very difficult task in growing cloud aura. In industries cloud
arena is fastly growing, all the industries now a days are not interested in setting up their
own environment investing more money instead of that all prefer cloud only. The trust of the
cloud is still challenging issue in cloud arena.
The challenging issues such as privacy, security and dependability as made the trust
management and security top rank among cloud computing. One way to establish a hope and
faith for cloud provides in fulfilling of Service Level Agreements (SLA). The SLA is
unclear and they are inconsistence in nature, they lag behind to provide trust between cloud
consumer and provider. The summarization of the SLA is inconsistence even though they
offer services between cloud providers. Based on the SLA customers can’t identify the trust
of cloud producers. Consumers are responsible for checking SLA transgression and they
should only inform to the service provider for compensation. Feedback of the consumer is a
good root to achieve trust of service provider services.
In this project the trust manager facilitates to check the faith of the other party based
on the feedback given by the user/data owner where they are behind the scene and the
feedback is given during previous transaction. For the future interaction the “reputation” of
the unnamed providers can arbitrate whether they have met the minimum trust. For
examples based on buyers and sellers reputation given many participants decides to do
transaction on online sites. Collusion and Sybil attacks are experienced by many service
providers so there must be novel techniques to overcome these attacks and protect the
credibility of faith feedback.
The choice of cloud computing step-up privacy concerns. When the on demand
services take care of personal information like data, storing the file, processing then privacy
needs to taken into the scene. If anything as a service is to process the data which is public
then privacy threats are low. The high privacy threats are found when the data are
dynamically personalized and consumer has dynamic interaction with the service providers
which will include very sensitive data.
There are several cases where rules of privacy are broken like leakage of sensitive
information. Protection of the On-demand services is not so easy, they experience attacks
from users. Attackers try to damage the services provided by the service provider by giving
multiple negative feedbacks or by registering with multiple accounts. There are several
challenges in detecting such malicious behaviors. First thing is when old users leave and
new consumers join the cloud arena. This type of activity makes detection of malicious
attackers more challenge. Second is when users have many accounts on same cloud service,
this type of activity makes difficult to check the Sybil attack. At last it is difficult to guess
when such malicious activities happen.
A trust management service provides an interface between users and service
provider’s services for useful trust management. However warranting the availability of trust
as a service is a challenging problem because of the doubtful users and nature of the cloud
arena is dynamic also. The “Trust Management” which is provided as a service should be
supple to function in cloud arena.
1.1 PURPOSE
Purpose of the project is to set up a framework which provides a eminence trust
management in cloud aura. The project is designed such that it provides a user-friendly
environment for the users and cloud providers. The cloud consumers can add their feedbacks
and survey the trust of the cloud services provided by the cloud service providers. On the
other side cloud service providers can give advertisements on their services in trust module
to calculate and use it. There are benefits for both the parties that is user and data owner.
In this project the trust manger gives the permission to the cloud user to give the
feedback about the trustworthiness of a current cloud used by the user. It also gives facility
to select a cloud service of user’s choice. It also provides service like viewing the credibility
factors and selecting it. The trust module allows the consumer to search the services they
need like Saas, Paas, Iaas. The filtering methods facilities are also provided by this module.
1.2 OBJECTIVES
To protect cloud services against malicious user.
To preserve privacy of consumers
1.3 VISION
The project is proposed that is resilient against the malicious users who give the wrong
feedback about the cloud service. Proposed approach offers Trust as a Service that delivers
an adaptive and robust credibility model that provides decentralized trust management
service.
1.4 SCOPE OF THE PROJECT
The users can choose the reliable and faithful service providers like on Google, eBay and
many more where reputation systems and trust systems are used in much application.
Customers need to select similar applications in these approaches. The existing trust system
is based on the customer’s feedback only than any other sources and information’s.
Additional parameters are required in selecting the trust cloud service providers in markets.
The trust system will support the customers in judging before choosing the good trust on-
demand providers.
We have provided a brief summary of the design part as well as implementation
part:- Cloud Armor is a framework for prominence based trust management in cloud aura.
Trust is delivered as services (TaaS) in this proposed system where feedback is in a
decentralized way.
The Scope of this project is to provide a service which includes trust as main part:
1. A protocol is used to validate the feedback credibility and take care of privacy information
of user.
2. The trust module for measuring the reputation of the cloud service and compare the trust
provided from TM to cloud services.
3. Detecting collusion and Sybil attack.
1.5 PROBLEM STATEMENT
Design a Trust Management which is given as a service is to validate feedback
credibility and protect user’s privacy.
The credibility model should detect collusion and Sybil attack.
The credibility model should measure the reputation of feedbacks to protect services
offered by cloud from malicious users and compare trust of services provided by
cloud service providers
Providing trust services is important challenge as cloud aura is dynamic in nature.
CHAPTER 2
LITRATURE SURVEY
For growth of cloud computing trust is very much important. In the cloud aura many
solutions have been forthput to manage the trust feedback; trust feedback credibility
determination is mostly neglected. In this project trust is provided as a service to increase
the trust managing in cloud aura. Prototype system validates the approaches used to make
trust system.
2.1 LITERATURE SURVEY 1
Paper Title : Improving data integrity on cloud storage services
Publisher : International Journal
Theme:
Cloud is used everywhere to its convenience it may be simple data analytic or it may
be composite applications.
Local computer have no much work to do as the applications run on cloud server.
The cloud network handles them.
The user only has to run the cloud system interface software, which may be Web
browser and all the other things are taken care by cloud’s network.
Advantages:
User is assured that all the user data is protected.
Any changes to the data stored in cloud are maintained easily.
Processing of data, assurance and protection to the data stored are in the hands of
user.
Disadvantages:
For file distribution preparation, the system relies heavily on erasure correcting code.
Proposed System:
When the applications, data are migrated to cloud privacy risks are examined.
Trust to the data store is provided.
Update, append and delete activities are done dynamically
2.2 LITERATURE SURVEY 2
Paper Title : Privacy Risk, Security in Cloud Platforms
Publisher : Athens university
Authors : Marianthi Theoharidou
Theme:
Valuating the privacy in cloud aura is difficult challenge.
This paper identifies the threats, takes care of clients and service providers in order
to success the privacy issues and checks the privacy assessment.
Advantages:
For liability risk determination is important as it is a central part of the process.
CSP partially takes the risk.
As task is shared among different stakeholders protecting the customer information
is done.
Disadvantages:
Selecting correct security profile is difficult and also choosing privacy of
cloud is also difficult.
Proposed system :
In proposed system the trust manager will maintain the login authorization.
If any misleading activities happens then the details of that user is sent to the list of
attackers.
The threats like collusion and Sybil is detected.
Recovery of modified data is done.
Objectives:
Zero knowledge protocol is used where set of rules are defined to protect the data
and maintain the trust of cloud.
The project is developed by using java tools which is acting as search engine.
The existing systems provides some drawbacks i.e., It is known that a cloud service
get attacked by malicious behaviors from its users, trusting the cloud providers is also
difficult task. SLAs are inconsistence even though they provide services which have
similar functions. Using SLA customers can’t identify the trust of the system. In this project
the system provides a framework which offers trust as the service to increase the trust
management. In this project the system provides a credible model where trust and malicious
feedback is detected and differentiated. Using “service Oriented Architecture” the system
proposes a framework to offer trust as the service. It has ability to detect malicious behavior
like collusion attack and Sybil attack.
2.3 DISADVANTAGES OF EXISTING SYSTEM:
Providing TMS is difficult problem because unnamed users and cloud aura
character is dynamic.
A Sybil attack performed on cloud service is difficult to detect.
Giving negative feedback about the cloud to mislead the customers.
Creating several accounts and try to mislead the consumer and creating bad
impression about cloud service provider
2.4 PROPOSED SYSTEM:
Collecting all the feedbacks is best source to guide the trust of cloud service. The
project provides a technique to collect the feedback and detect the attacks.
This project identifies the collusion and Sybil attacks.
In this proposed system limitation are applied to feedback about cloud services and
downloading the file so that if any user tries to overcome the limitation then they are
considered as attackers or malicious users.
CHAPTER 3
SOFTWARE REQUIREMENT SPECIFICATION
Preparation about “Software Requirement specification (SRS)” is most important
activity. In the modern world problems are more complex making developers difficult to
known about the problem fully and work according to goal. In present time is considered as
one of the most important requirement.
3.1 PURPOSE
SRS aims to list out the requirement of users and system in particular way. All the
software needed and constraints are defined by SRS. Overall design plan is given by
SRS. After understanding the SRS the user will be able to guess the proposed system.
Software design is done by SRS. All the necessary requirements of the project is done by
the software requirement specification.
3.2 SYSTEM INTERFACE:
Interface is a tool where it is applicable to both software and hardware and
interaction among the components is done by this only. Interface allows components to
communicate with each other whether it may be hardware or software. A monitor or a
keyboard communicate through peripheral devices called as computing interface, they are
bi-directional. Internet and computer interact with the help of internet protocol. Mouse and
microphones are unidirectional.
3.3 HARDWARE INTERFACE:
Hardware interfaces come into picture by the systems among many of the
components like various storage media, input devices and output device, etc. A hardware
interface may be anything like mechanical, electrical and logical signals.
3.4 SOFTWARE INTERFACE:
The software interfaces defines the connections among product and software
components like operating system, libraries, databases, tools. It refers to the documentation
where it contains detailed information about application program and interface protocols. It
pinpoints the data shared across software components. It specifies the constraints needed for
implementation. Access to memory, storage, CPU is provided by the software.
3.5 EXTERNAL INTERFACES
This section provides all input to system and outputs from system in detailed
manner. It also tells about hardware interfaces, software interfaces and communication
interfaces. It also provides prototypes the user interface uses.
3.5.1 USER INTERFACE
When the project runs, the first thing seen on the GUI is the login page with
controls to enter username and password. This page should also enable registration for a
first time user. Once a user authenticates him/her on the login page, he/she is
redirected to his/her profile page.
HTML or JSP tools will be required to code the user interface. The Dynamic Web
Application provides a convenient environment to code the web application in Java.
3.5.2 OTHER SOFTWARE INTERFACES
The interfaces required are the ones between the web application and its server i.e.
interfaces to Cloud Consumer/Data Owner and between the server and the database or
the DB interface.
The Java programming language provides facilities to interface between a Java
web application and a database like MySQL.
3.6 PRODUCT FUNCTIONS:
3.6.1 Function: Cloud Consumer Registration
Description: Maintain database of users and their profiles based on
registration.
Inputs: Name, Username and
Password
Source:
GUI
Outputs: Redirect the user to his/her profile page on registration with appropriate
message, if the Username is not already present. If the Username entered during
registration is not unique, then an appropriate message should be thrown.
Destination:
GUI
Action: Compare the Username entered with the ones in the database to check
its availability. If unavailable, then ask for a different Username; else create a new record
in the database and save the entered details.
Requires: Existing Usernames to maintain an unique Username for each user is
needed.
Pre-condition: Name and Usernames should start with an alphabet and Password should
contain at least one alphabet and one numeric character and one special character.
Post-condition:
None
Side effects:
None
3.6.2 Function: Login Authentication:
Description: Provide access to user profiles upon correct login
authentication.
Inputs: Username and Password.
Outputs: Redirect the user to his/her profile page on valid authentication. If the
Username and Password do not match with the database entries, then an appropriate
message should be thrown.
Destination: GUI
Action: Compare the Username and Password entered with the respective fields among
the database entries. If a match is found, then redirect the user to his/her profile page. Else
redirect the user to the registration page.
Requires: Existing Username and Passwords for the comparison is needed.
3.6.3 Function: Enable to comment/send feedback about the Cloud
services:
Description: Accepts feedback from authentic users in the form of short-text messages
and perform certain actions based on their classification.
Inputs: Short text message and cloud service providers name.
Source: GUI.
Outputs: Feedback will be sent to trust manager and stored in the persistent
media.
Destination: GUI
Action: Perform filtering of end users feedback with collected reserved
keywords. If the text of feedback matches to the keywords then it will group
under positive or negative feedbacks.
3.6.4 Function: Detection of collusion attack:
Description: Accepts feedback from authentic users in the form of short-
text messages and perform certain actions based on their classification.
Inputs: Feedback from the user.
Source: GUI.
Outputs: Feedback will be sent to trust manager and stored in the persistent
media.
Action: Perform filtering of end users feedback with collected reserved
keywords. If the text of feedback matches to the keywords then it will group
under positive or negative feedbacks. Perform matching operation of
individual unit strings with set of reserved keywords and iterate the same
process over the set of all the keywords. If the negative keywords match
with the feedback given by the user then it is detected as malicious behavior.
The user is considered as collusion attacker.
3.6.4 Function: Detection of Sybil attack:
Description: Accepts the user request to download the file
Inputs: User name, file name and secret key.
Source: GUI.
Outputs: message pops as download expiries and the user is put under
Sybil attacker.
Action: Check the file name and user name is the first action. Check the
user transaction count of the user and maximum permissible transaction
count. If it matches permit the user to download the file and decrease the
user permission transaction count. If matching returns false populate error
message mean while track the user details and considered as Sybil attack.
3.7 SOFTWARE SPECIFICATION:
Operating System : Windows Family
Coding Language : J2EE (JSP, Servlet)
Database : MYSQL
Web Server : Tomcat 6.0
3.8HARDWARE SPECIFICATION:
System : Pentium IV
Hard Disk : 40 GB
Ram : 1 GB
3.9 NON FUNCTIONAL REQUIREMENTS:
The requirements which are not directly referred to a particular functions delivered
by the system are known as “Non – Functional Requirements”. The response time, reliability
and storage all come under this category.
The following non-functional requirements are worthy of attention.
Security: secured communication must be provided by the system between Clouds
and
Energy Efficiency: receiving file from cloud to the user how much energy is
required.
Reliability: performance and reliable of the system
3.10 FUNCTIONAL AND NON FUNCTIONAL MATRIX:
FUNCTIONAL file access control at cloud server based on the Cloud
Account, Send Trustworthiness of cloud, View all Feedback
by the end users(List Negative and Positive Feedbacks, end
user authentication, request secret key, download files from
cloud server.
NON-FUNCTIONAL Data Owner never monitors the Cloud activities
EXTERNAL LAN ,WAN, routers
INTERFACE
PERFORMANCE Finding attackers data, File Sharing between Cloud Server
and Remote User, Blocking the File Hackers in the cloud,
List all attackers and no of time attacked
ATTRIBUTES Cloud server, Data owner, user and, Find Trust Worthy
CHAPTER 4
DESIGN
Representing the software from collected the requirements id done by the design
phase. The quality of software is assessed before coding. Once all the requirements is
collected and examined, we should identify how the system should construct to do task.
The design phase is differentiated into two parts firstly system design and second is
detailed design.
SYSTEM DESIGN:
The goal of system design is to identify modules which are in the system, giving
details about the modules. How each module will interact with other to produce expected
outputs. What are all the components needed to system is defined by this phase.
DETAILED DESIGN:
In this phase internal logic of every module which is specified in the system design
phase are decided. If only concentrates on designing the logic of every module. The detail
design phase explains how components identified in system design are implemented on
software.
DATA FLOW DIAGRAM
Data-flow phase tells directly how data is used or processed in the system.
CLASS DIAGRAM:
The class diagram is the basic block of object oriented. General modeling for
systematic application and detailed modeling is used for translating models into code.
4.1 SYSTEM DESIGN:
This project intends to offer a service to protect the cloud consumers by bifurcating
faith of the cloud services from the rest of the user. This service detects the cloud offered
services and by collecting feedbacks from the cloud consumers it rates their credibility.
4.1.1 SYSTEM ARCHITECTURE:
The architecture represents the framework for eminence based trust management.
The framework is dependent on “service oriented architecture” where services provided in
trust. The trust management provides an interface to the user so that user can give comments
and also enquire the results about the trust. There are three different layers:
Data Owner layer
Cloud Consumer Layer
Trust Manager Layer
The architecture below depicts the services offered by the cloud providers, can check the
trust of cloud and can give the feedback about cloud services.
Trust data furnishing: Developing unique methods for cloud service to
discover the service and for collecting the feedback.
Credibility and trust estimation: Developing a functions to handle request
from user about trust assessments where loyalty of services are compared and
faith feedback are collected.
Trust Based Cloud Services guidance: develop a filtering mechanism to guide
trustworthy about cloud services which satisfies the consumer’s needs.
The Cloud service provider Layer: This layer tells about services like software,
platform and infrastructure as a service which are offered by the cloud service
provider. These cloud services can be used by web portal and it is resided on search
machines like google and yahoo. The interaction for this layer is between user and
trust manager. Cloud providers can advertise about the services offered by them on
web.
The Trust Manager Layer: This layer contains many nodes which are placed on
many cloud auras. These nodes provide an interface so that the user can give their
feedback about the services and find trust about the cloud in the decentralized way.
Interactions for this layer include:
Interaction is between cloud services and cloud providers.
Advertising about trust services through internet.
Zero-Knowledge (ZKC2P) protocol interactions enabling services as
a trust to prove the credibility of a wanted consumer’s feedback.
The Cloud User or Consumer Layer: This layer contains many users who will use
the cloud services. In this layer user can discover new services in cloud and other
services from the internet. User can give feedback or enquire about the faith of a
specified cloud this is what interaction between service and trust. User will register
with their credentials in IDM before using trust service.
Cloud Server 1
DATA Cloud Server 2
Select and
OWNER upload data
1) Register, Login
2) Browse, Upload
Cloud Server 3
3) Verify
4) Delete
5) View Cloud Details
6) Send Trustworthiness of cloud 1. Find Reputation
[Link] Trust Worthy Cloud Server 4
[Link] Service
Time
[Link] and Memory
1) View Cloud
TRUST MANAGER Files
1) Provide Login Authorization 2) View
2) View all cloud trust based Registered
on file attack
Users
3) View all Feedback by the
end users(List Negative and
Positive Feedbacks)
Cloud Consumer
4) List no of users in
Iaas,Saas,Paas
1) Register, Login
5) View Trustworthiness of
2) Request a file cloud
3) Feedback about the Data
Malicious User
6) List all attackers and no
of time attacked
Figure 1: System Architecture
4.2 DETAILED DESIGN:
A detail design pattern is not completed fully, we can’t implement the code. It is
only description about solving the problem which can be used in different situations. The
interactions and relationships between objects and classes are shown by Object-Oriented
patterns.
4.2.1 FLOW DIAGRAM
Flow diagram explains about nature and flow of program in step by step.
The figure below depicts the flow diagram of the project. The flow diagram explains as
follows:
Data Owner has to first register with his/her details via name, password, email id,
phone number and other details.
Data Owner has to Login with username and password to purchase the virtual
machine to store the files.
Data Owner has to upload the file
If virtual machine is not purchased data owner can’t upload the file, else he/she can
upload the file to registered cloud.
The Trust manager can check the user details and cloud service provider details,
secret keys.
The trust manager and data owner can check the files and secret keys.
Cloud Consumer has to register with his/her details.
Cloud consumer has login to request secret key and to download the file.
If the secret key, file name and cloud service provider name matches the cloud
consumer can access the file and download it.
OWNER
UPLOAD FILES
no
Cannot upload
Upload to reg
cloud server
analloc
yes
Store Files in
Cloud (CS1, CS2,
corresponding cloud
CS3,CS4)
Check files File name or skey not
or secret correct
key
YES
Access the Files
Download file
Correct files File name or skey not
name or correct
secret key
RECEIVER
Figure 2: Flow diagram
4.3 DATA FLOW DIAGRAM:
A Data Flow Diagram tells the how data flows through system. How data flows in
sequence manner are showed by Data Flow figures. When these diagrams are used to
document the software design they are steps inside or program functions.
The Data Flow Diagram (DFD) consists of three levels they are level 0, l and 2.
4.3.1 Level 0 DFD
The level 0 is to draw context-level diagram. System and entities which are outside is
explained in this. It is a initial level diagram shows details about system modeled.
The diagram here explains the communication between the Data Owner and the
Cloud server. The Data Owner has to register with the cloud server to use the services
offered by the cloud service providers.
High level view of the project is explained in this level. How the cloud server will
interact with the Data Owner.
Level 0
Selects the Cloud Server 1
cloud server
Cloud Server 2
register cloud Cloud Server 3
Data Owner
server
Cloud Server 4
Figure 3: Data Flow Diagram Level 0 Diagram.
4.3.2 Level – 1 DFD
The processes which are main in the system are shown in this level. Until pseudo the
code is obtained each process are divided. The processes which are identified in this level
are further taken into level 2 diagrams.
The main processes are classified as under:
1. When application initiate ,System required to do some configuration mapping
between UserRole, Database table (which users with UserRole can access) and Type
of database query (ex, Select, Update, Delete )
2. For first time request from user to logged into system , Trust Manager will generate
unique id and keep it till end of user session
3. For all subsequent requests coming to application, Trust manager will check all
unique id. If request generating unique id is not available in Database then request is
called as invalid request.
4. The data owner can upload the file, verify the data uploaded, find the cloud trust,
find the attackers.
5. The trust manager can view all cloud files.
6. The trust manager can send trustworthiness of the cloud to data owner.
1. Upload file
Level 1 [Link] data
[Link] Cloud
trust
Cloud Server 1
[Link] Type of
attackers
Data Owner Cloud
Login Cloud Server 2
Server
Send Cloud Server 3
Provides login Trustworthine
operation for data ss of cloud
owner
TRUST View all the cloud Cloud Server 4
MANAGER files
Figure 4: Level-1 Data Flow Diagram.
4.3.3 DATA FLOW DIAGRAM LEVEL-2
The flow of the process are more detailed in second level DFD
Configuration or mapping will be done by Configuration Module
Mapping is done between Database table and database query will be generated.
Loading of Application context is done by configuration module.
Data owner has to get register to the cloud server
Data owner will login to the corresponding cloud server he got registered.
Data owner encrypt will upload file to the cloud server
Data owner verifies the file he uploaded either it is safe or not.
Data owner can view, how many file has been uploaded to the corresponding cloud
servers
Data owner will send file to trust manager to store the data owner file to the
corresponding cloud servers. The cloud server manages a cloud to provide data
storage service.
Trust manager provides login authorization for both data owner and the end user.
Trust manager can view all the cloud status
Trust manager can view the feed backs given by end user and lists all positive and
negative feed backs. Cloud consumer first has to register to the cloud server which
particular cloud he has to use.
Cloud consumer has to login to the cloud he got registered.
Cloud consumer feedback about the data
Level -3
Cloud consumer Req File
Cloud Servers (cs1, cs2, cs3,cs4)
Authorize
the file Check
fname
F
and sk
Capture malicious user and Res
Enter correct File name or Secret
Figure 5: Data flow Diagram Level 2
Key
4.5 USE CASE DIAGRAM:
Use case diagrams are the functionalities of the system and it represents the actors.
The actors can be user or internal applications or external applications where they interact
with the system.
When we draw a use case diagram we have to consider following items:
Functionality of the systems which should be represented.
Actors.
Relations between actors and use case.
The UseCase diagram here depicts the functions of the three members that is Data
Owner, Trust Manager and Cloud Consumer.
The Data Owner functions are:
Register and login to the cloud.
Upload a file to the cloud
Check whether file is safe or not.
View the cloud details.
The Trust Manager functions:
Provide login authorization to the data owner and cloud consumer.
Checks the Sybil and collusion attack
Checks the feedback given by the cloud consumer.
Verify the File name and owner name
Obtain the transaction count of the user
Obtain the maximum permissible transaction count for the user
Verify the user transaction count and maximum permissible transaction count
If matching results true permit the user to download the file (decrease the user
permissible transaction count )
If matching returns false populate the error message (mean while track his details
under Sybil attack)
The Cloud consumer functions:
Request secret key.
Obtaining the secret key.
Receive the file.
Figure 6: Use Case Diagram
4.6 SEQUENCE DIAGRAM:
Flow of the messages, events and actions between objects are defined by the
sequence diagram.
In Sequence Diagram:
1. Sending Message is indicated by
2. Returning Response is indicated by ------
3. Processing indicated by
4. Activation of process
The sequence diagram explains the how each module works. The sequence diagram
explains as follows:
Firstly data owner has to register with the cloud server.
Confirmation of the registration whether registered successfully or not.
Trust manager provides the login authorization to the data owner.
Data owner can upload the file to the cloud.
File uploads confirmation from the cloud server.
Trust manager provides the login authorization to the cloud consumer.
Cloud consumer can register to the cloud server.
Registration confirmation from the cloud server to the cloud consumer.
Trust manager will list the number of users in the cloud services.
Trust manager lists the attacker’s details.
Cloud consumer can request for the file from the cloud.
Cloud consumer can view the files downloaded.
Figure 7: Sequence diagram.
4.7 CLASS DIAGRAM
Data owner Cloud server
ownerowner ownerowner
View cloud files, view registered
Register, login, browse, upload,
users
Methods verify, delete, view cloud details Methods
,trust manager
File name, owner name, public
File name, cloud name, ip
address, secret key, reg details key, secret key, user details, reg
Member Member
s details, attackers, exit
s
Cloud consumer
Register, Login, Request a file, Malicious user
Methods
Feedback about the Data
Methods
Collusion Attacks ,Sybil Attacks
Filename, Cloud Ip, secret Key,
Member
cloud Name,receive
s Cloud consumer detils, cloud
Member
Trust manager s servers files
Provide Login Authorization,
View all cloud trust , View all
Methods Feedback, List no of users, View
Trustworthiness
Owner name, cloud users name,
attackers list, cloud consumer
feed backs, cloud
Member
services(ias,pas,sas)
s
Figure 8: Class diagram
CHAPTER 5
IMPLEMENTATION
The goal of implementation is to create a code, testing is done for required output
and corrects the errors during execution of the program. System implementation involves
testing the tools created on setup and finding that the data is generated in the central
manager database.
The source code is implemented in java programming language. We use JDK
version 8.1. The back-end consists of the database that maintains the user data and other
data that is to be displayed on the GUI. The database is implemented in MYSQL query
language. Finally the operating system is used is windows 7.
5.1 ORGANIZATION:
The name of the folder containing the entire project is CloudArmour. We can open it as
java project.
5.1.1 Directory Structure
The directory structure is in the Project Explorer window. The project contains:
WebPages: contains all Java Script files.
Libraries: Contains all the jar files required for the project.
Configuration files: Contains the files like manifest.
Figure 9: Main directory structure.
Figure 10: web page content.
5.2 MODULE DESCRIPTION:
In this section we describe the different modules:
5.2.1 DATA OWNER:
In this module, initially the data owner has to get register to the cloud server (CS1,
CS2, CS3, CS4).Data owner will login to the corresponding cloud server he got registered.
Data owner encrypt will upload file to the cloud server (CS1, CS2, CS3, CS4) Data owner
verifies the file he uploaded either it is safe or not. Data owner can view, how many file has
been uploaded to the corresponding cloud servers(CS1, CS2, CS3, CS4) Data owner will
send file to trust manager to store the data owner file to the corresponding cloud servers
(CS1, CS2, CS3, CS4).
The methods used in this module are Register, login, browse, upload, verify, and
delete, view cloud details, trust manager.
The [Link] page is used to register the cloud consumer or Data Owner with
their name, password, phone number, email id, cloud server. This page redirects to
[Link] pages.
The [Link] is the web page when user chooses to log into the application at the
main page. The file contains the submission of the form elements like username and
password to user_main.jsp which after verifying the user data from the database
starts the current session.
The [Link] file contains the java classes for setting up the database connectivity.
To upload a file [Link] page is used, where data owner has to select the cloud,
choose the file to upload, and encrypt the file and send to the cloud.
Reputation count can be seen by the data owner.
Can detect the collusion and Sybil attackers using [Link] page.
Data owner will view cloud details like name, mac address and file name.
5.2.2 CLOUD SERVER
Managing the cloud to assign storage facility is the work of cloud server. The file
containing the data are encrypted by using encryption algorithm and uploaded by data owner
to share with cloud consumer. To access the data file consumer should login to the cloud
service and then download it.
5.2.3 TRUST MANAGER
Trust manager provides login authorization for both data owner and the end user.
Trust manager can view all the cloud status .Trust manager can view the feed backs given by
end user and lists all positive and negative feed backs. Trust manager lists no of users in
cloud services(IAAS,PAAS,SAAS).Trust manager can view the attackers in cloud
servers(CS1,CS2,CS3,CS4) and the no of time attacked.
The algorithm used here is: Credibility algorithm.
Input is s, Output is equal toTr(s)
Count |Vc(c,s)| /* total number of new feedback coming by consumer is counted by
Trust Manager */
f |Vc(c,s) >= e Cache( c) */ credibility factors are calculate */
end the if stmt
Count |V(s)| cache/* trust feedback counted */
If |V(s)| cache >= eCache(s) then /* determine recalculation required */
End if.
5.2.4 CLOUD CONSUMER
Cloud consumer first has to register to the cloud server (CS1, CS2, CS3, CS4) which
particular cloud he has to use. Cloud consumer has to login to the cloud he got registered.
Cloud consumer feedback about the data (positive or negative feedback)
5.2.5 COLLUSION ATTACK DETECTION
Malicious users give many misleading feedbacks to alter the results for cloud
services. The feedback given by the number of users helps to determine the credibility of the
cloud service. When several attackers tries to mislead the feedback means tries to give
negative feedbacks about the cloud services such type of attacks are called collusion attack.
This type of attack is detected in this project by providing limitation to the user in giving the
feedback.
Step1: Collecting all possible reserved keywords representing type of the FeedBack
(Growable over a period of time).
Collect all reserved word known: String t = all possible reserved words;
Step 2: Obtain the real time feedback/comments provided by the user
String cname=[Link]("t1");
String query="select * from feedback where cname='"+cname+"' ";
Step 3: Store the feedback given by the user in persistence media.
ResultSet rs=[Link](query);
Step 4: Perform filtering of the End user provided feedback with the set of collected
reserved keywords
a) Split the end user feed back Single line String into possible smallest strings
b) Store sting units into persistence storage
c) Perform matching of individual unit strings with set of reserved keywords
And iterate the same process over the list/ set of all the keywords
rs=[Link](1);// get the id of the user
s2=get the String(2); // get the name
s3=get the String(3); //
s5=get the String(4);
if([Link](t(x))>=0 || [Link](t(y))>=0|| [Link](t1)>=0 || [Link](t2)>=0 so on
compared to all the key words.
5.2.6 SYBIL ATTACK DETECTION:
In Sybil attack the attacker’s tries to download the files from other user’s sessions.
Somehow the attackers get the information about the files of the users and the attacker will
download the file and get the information. Detecting this type of attack is difficult, applying
limitation to the downloading access to the user will reduce this type of attack.
Step 1: Request secret key
String strQuery = “select key2 from cfiles where cname = ‘”+cname+” and
fname=”+fname” and oname=”+oname+”;
Step 2: Obtaining the secret key verify the secret key.
String sk=[Link]("t4");
Step 3: Obtain file name and owner name
String fname=[Link]("t2");
String oname=[Link]("t3");
Step 4: Verify the File name and owner name and obtain the transaction count of the user.
String query2="select count(*) from udownloads where oname='"+uname+"' and
cname='"+cname+"' and dt='"+strDate+"'";
Step 5: Obtain the maximum permissible transaction count for the user and Verify the user
transaction count and maximum permissible transaction count
if(i>2)
String ip_h = [Link]();
Step 6: If matching results true permit the user to download the file (decrease the user
permissible transaction count )
String query="select * from cfiles where cname='"+cname+"' and
fname='"+fname+"' and oname='"+oname+"' and key2='"+sk+"' ";
ResultSet rs=[Link](query);
Step 7: If matching returns false populate the error message (mean while track his details
under sybill atack)
if(i>2)
{
String ip_h = [Link]();
String host_h = [Link]();
[Link](" insert into Attackers values ('"+uname+"','"+cname+"','Downloading File
to the Cloud','"+ip_h+"','"+host_h+"','"+dt+"') ");
[Link]("LIMIT FOR DOWNLOADING IS EXPIRED...!"); }
5.2.7 ENCRYPTION ALGORITHM:
When the Data Owner tries to upload the file to the cloud the data has to be
encrypted first and then sent to the cloud. The encryption algorithm used is Base 64
Encrption Algorithm
Step 1: Define a codes key(A-Z,a-z,0-9)
Step 2: Define a message to be encrypted (File content)(“Hi How are u”)
[Link](Cipher.ENCRYPT_MODE, key);
Step 3: Store in Persistence media.
String encryptedValue = new String([Link]([Link]()));
5.2.8 DECRYPTION ALGORITHM:
When cloud consumer wants to download a file, the file has to decrypt first and then
download it. The algorithm used here also is Base 64 decryption algorithm.
Step 1: Give Code key as input
Step 2: Provide message as input
Step 3: Perform decryption
[Link](Cipher.DECRYPT_MODE, key1);
decryption is done by below code:
String decryptedValue = new
String([Link]([Link]()));
5.2.9 DATABASE CONNECTION:
Data base connection has to be done to connect mysql and java application.
Connection connection = null;
Giving the class name:
[Link]("[Link]");
Providing username and password:
jdbc:mysql://localhost:3307/ctrust","root","admin"
Tables created in mysql. The tables are stored in web content folder in eclipse by
table folder name. First we have to create a Database by name ctrust and then use the
database. Under the created database tables have been created.
Creating a database and using it:
create database ctrust;
use ctrust;
Creating a user table under ctrust database:
create table user ( id of int type autoincrement, uname text, pwd as text, dob
as text, email as text, mobile as text, location as text, utype as text, stype
text, cname text, imagess longblob, count int(11) default NULL, sk text,
PRIMARY KEY (id) );
Creating a admin table:
Create table admin with username of VARCHAR, password of
VARCHAR(50)
Creating a Cloud table:
Create table cloud with username of VARCHAR(50), password of the type
VARCHAR(50), cloud of VARCHAR(50)
Insert values into cloud table:
insert into cloud values ('CS1','CS1','CS1');
insert into cloud values ('CS2','CS2','CS2');
insert into cloud values ('CS3','CS3','CS3');
insert into cloud values ('CS4','CS4','CS4');
Create table cfile:
create table cfiles(id int auto_increment, oname text, cname text, fname text,
mac text, key1 text, key2 text, pt text, ct text, dt text, PRIMARY KEY (id));
Create table feedback:
create table feedback1( id int auto_increment, oname text, cname text,
feedback text, dt text, PRIMARY KEY (id));
CHAPTER 6
TESTING
6.1 TESTING:
The goal of the testing detects the errors by testing each component and corrects it.
The module may be functions or an objects or a module. The components are integrated
together during system testing. Testing of each module should meet its functional
requirements. The components are tested in different combinations it should meet its
requirements.
Hardware
Hard Disk = 250 GB
1 GB RAM
Software
OS ( Operating system) = Windows 7
JDK 8.u71, Tomcat server
The software is tested using these configurations.
6.1.1 UNIT TESTING:
In unit testing every module’s interface is tested to ensure the correct flow of data
that the system takes into the modules and outputs the correct results. This type of testing is
done during programming only so that if module fails correction can be done easily. At last
of this testing each unit was working correctly.
6.1.2 TESTING STRATEGY:
1. Features tested are – The features tested are operations of individual component.
Check whether entire program runs properly.
2. Items tested are – The items tested consists of all the single units or functions,
which forms the entire system. The items are Registration application page, Login
page , Deploy the application to Cloud , Uploading the file, downloading the file,
encrypt the file, detection of collusion and Sybil attack, view the trust feedback.
3. Purpose of testing – Verify the unit functions of the main project source.
4. Pass/Fail Criteria – Pass or fail.
6.1.3 UNIT TESTING: REGISTRATION MODULE APPLICATION
The Table here shows the test case of Registration page.
Sl = Test 1 : - UTC1
Name of Test: - “Registration”
Item tested: - Registration application page
Name
Password
DOB
Mail-id
Sample Input: -
Location
User type
Cloud
Photo
Real output: - Registered message should be displayed
`Actual output: - Same
Remarks: - Pass
Table 6.1 Unit Test Case (UTC) for Registration
6.1.4 UNIT TESTING OF LOGIN PAGE APPLICATION
The Table here shows the unit test case of Login
S2 = Test 2 : - UTC2
Test Name : - “Login”
Tested item: - Login page
Sample Input: - Username, Password, user type and cloud
Expected output: - Login successfully and go to next page
Actual output: - Expected output is success.
Remarks: - Successful
Table 6.2 Unit Test Case: Login
6.1.5 UNIT TEST OF FILE UPLOAD:
The Table here shows the unit test case for uploading the file.
S3 = Test 3 : - UTC-3
Test Name : - upload module
Item tested: - Uploading the file
Sample Input: - Cloud server, file name,
Uploaded successfully message should display if
Expected output: -
uploaded else error message should display.
Actual output: - Same
Remarks: - Pass
Table 6.3 : file uploads UT
6.1.6 UNIT TESTING OF SENDING FEEDBACK:
The Table here shows the unit test case for sending feedback.
S4 = Test 4 : - UTC4
Test Name : - Unit Testing: Sending feedback module
Item being tested: - Feedback sent or not
Sample Input: - Cloud server, file name,
Expected output: - Feedback sent messages display
Real output: - Same
Remarks: - Pass
Table 6.4: sending feedback UT
6.1.7 UNIT TESTING OF FINDING TRUST WORTH OF CLOUD
SERVICE:
The Table 6.5 shows the unit test case for finding trust worthy of the cloud services.
S5 = Test Case : - UTC-5
Test Name : - Unit Testing for finding trust of cloud module
Item being tested: - Total number of collusion and Sybil attacks
Sample Input: - Cloud server
Expected output: - Display total number of collusion and Sybil attack
Real output: - Same
Remarks: - Pass
Table 6.5 trust of cloud UT
6.2 INTEGRATION TESTING
While connecting between two modules data can be lost due to the interface problem
and may not produce expected output. Integration testing is symmetric way testing. All the
modules are combined together and tested and then entire program is tested.
6.2.1 TESTING STRATEGY
Features tested –Integration of two or more components are tested like Login and
Registration, Cloud Server.
Items tested –Enter valid user id and password click on submit button, select setting
in applications.
Testing purpose – integrating all the modules testing whether they are working
correctly or not.
Pass/Fail Criteria- combining the module and testing, check whether the results are
pass or fail.
6.2.2 INTEGRATION TESTING: LOGIN AND REGISTRATION
Sl = Test Case : - ITC-1
Test Name: - Integration testing: “Login_Registration”
enter valid user id and password click on submit
Item tested: -
button
Sample Input: - user name and password
Expected output: - Valid user and file uploaded successfully.
Actual output: - Same
Remarks: - Pass
Table 6.6:Login_Registration IT
6.3 FUNCTIONAL TESTING
6.3.1. TESTING STRATEGY ARE:
Features tested –Functional testing on cloud server, User Module, Login Module.
Tested Items–Deploy the application to Cloud, Select project run as server, Enter
numbers in name text field, enter special character in name text field ,Enter blank
value in first name text field.
Purpose of testing – evaluating major functions
Pass/Fail Criteria – Pass or fail should.
6.3.2 FUNCTIONAL TESTING: PROJECT RUNNING
Sl = Test 1 : - FT1
Test name: - “CloudServer”
Tested Item: - Select project run as server
Sample Input: -
Application should start run if all the connection is
Expected output: -
proper on server
Real output: - Same
Remarks: - Pass
Table 6.7 Functional Test 1
6.3.3 FUNCTIONAL TESTING: USER MODULE STEP 1
S2 =Test 2 : - FT2
Test Name: - “User Module”
Item tested: - enter User name in name field
Sample Input: - name = Usha
Expected output: - Accept without any error
Real output: - Same
Remarks: - Pass
Table 6.8 FT 2
6.3.4 FUNCTIONAL TESTING: USER MODULE STEP 2
S3 = Test Case : - FTC-3
Test Name: - “User Module”
Item tested: - Special character in name text field
Sample Input: - name = usha@123
Expected output: - Invalid name and password message appears
Real output: - Same
Remarks: - Pass
Table 6.9 Functional Test 3
6.3.5 FUNCTIONAL TESTING: USER MODULE STEP3
S4 = Test Case : - FTC-4
Test Name: - “User Module”
Item tested: - Enter numbers in name text field
Sample Input: - name= 123456789
an error message showing "invalid first name " should be
Expected output: -
displayed when send button is clicked
Actual output: - As expected output
Remarks: - Pass
Table 6.10 Functional Test 4
6.3.6 FUNCTIONAL TESTING: USER MODULE STEP4
S5 = Test Case : - FTC-5
Test Name: - “User Module”
Item tested: - Enter blank value in first name text field
Sample Input: - name= BLANK
Expected output: - Wrong username message displays
Real output: - Same
Remarks: - Pass
Table 6.11 Functional Test 5
6.3.7 FUNCTIONAL TESTING: LOGIN MODULE STEP1
S6 = Test Case : - FTC-6
Test Name: - “Login Module”
Item tested: - enter User name in name field
Sample Input: - name = Usha and password = usha
Expected output: - Accepted
Real output: - Same
Remarks: - Pass
Table 6.12 Functional Test Case (FTC)
6.4 SYSTEM TESTING
After the above testing completed validation testing starts. The software should
function according to the consumer’s expectation. System is tested in count of requirement
specification.
6.4.1. TESTING STRATEGIES ARE:
[Link] SYSTEM TESTING 1: OPERATING SYSTEM
Sl = Test 1 : - ST1
Test Name: - OS Version
Tested Item :- OS
Sample Input: - Run on different os
Expected output: - Good in windows 7
Real output: - Same
Remarks: - Pass
Table 6.13 System Test 1 for OS versions
[Link] System Testing 2: IDE versions
The Table here shows the system test case for testing in Eclipse versions.
Test 2 : - ST 2
Test Name: - Eclipse
Item tested: - Eclipse
Sample Input: - Execute the program in java.
Output Expected: - Backward incompatible
Real Output:- Same
Remarks: - Pass
Table 6.14 System Test 2: IDE versions
All the tests done above are executed on system which supports the applications. As
all test cases done it was whole satisfactorily.
CONCLUSION AND FUTURE WORK
As we known the cloud nature it is dynamic and nontransparent. Providing a trust is
difficult task in cloud aura. We here introduced a technique which provide trust as services
so that the consumer can choose the better cloud services offered by providers. Here the
collusion and Sybil attack is detected. Future work is focus on combining different trust
techniques like reputation and as well as recommendation to increase the result. Managing
the Trust performance is another future work.
REFERENCES
[1] S. M. Khan and K. W. Hamlen, “Hatman: Intra-Cloud Trust Management for
Hadoop,” in Proc. CLOUD’12, 2012.
[2] S. Pearson, “Privacy, Security and Trust in Cloud Computing,” in Privacy and
Security for Cloud Computing, ser. Computer Communications and Networks, 2013,
pp. 3–42.
[3] J. Huang and D. M. Nicol, “Trust Mechanisms for Cloud Computing,” Journal of
Cloud Computing, vol. 2, no. 1, pp. 1–14, 2013.
[4] K. Hwang and D. Li, “Trusted Cloud Computing with Secure Resources and Data
Coloring,” IEEE Internet Computing, vol. 14, no. 5, pp. 14–22, 2010.
[5] M. Armbrust, A. Fox, R. Griffith, A. Joseph, R. Katz, A. Konwinski, G. Lee, D.
Patterson, A. Rabkin, I. Stoica, and M. Zaharia, “A View of Cloud Computing,”
Communications of the ACM, vol. 53, no. 4, pp. 50–58, 2010.
[6] S. Habib, S. Ries, and M. Muhlhauser, “Towards a Trust Management System for
Cloud Computing,” in Proc. of TrustCom’11, 2011.
[7] I. Brandic, S. Dustdar, T. Anstett, D. Schumm, F. Leymann, and R. Konrad,
“Compliant Cloud Computing (C3): Architecture and Language Support for User-
Driven Compliance Management in Clouds,” in Proc. Of CLOUD’10, 2010.
[8] W. Conner, A. Iyengar, T. Mikalsen, I. Rouvellou, and K. Nahrstedt, “A Trust
Management Framework for Service-Oriented Environments,” in Proc. of WWW’09,
2009.
[9] T. H. Noor, Q. Z. Sheng, and A. Alfazi, “Reputation Attacks Detection for Effective
Trust Assessment of Cloud Services,” in Proc. of TrustCom’13, 2013.
[10] T. H. Noor, Q. Z. Sheng, S. Zeadally, and J. Yu, “Trust Management of Services in
Cloud Environments: Obstacles and Solutions,” ACM Computing Surveys, vol. 46,
no. 1, pp. 12:1– 12:30, 2013.
[11] S. Pearson and A. Benameur, “Privacy, Security and Trust Issues Arising From
Cloud Computing,” in Proc. CloudCom’10, 2010.
[12] E. Bertino, F. Paci, R. Ferrini, and N. Shang, “Privacy-preserving Digital Identity
Management for Cloud Computing,” IEEE Data Eng. Bull, vol. 32, no. 1, pp. 21–27,
2009.
[13] E. Friedman, P. Resnick, and R. Sami, Algorithmic Game Theory. New York, USA:
Cambridge University Press, 2007, ch. Manipulation-Resistant Reputation Systems,
pp. 677 697.
[14] K. Ren, C. Wang, and Q. Wang, “Security Challenges for the Public Cloud,” IEEE
Internet Computing, vol. 16, no. 1, pp. 69– 73, 2012.
[15] F. Skopik, D. Schall, and S. Dustdar, “Start Trusting Strangers? Bootstrapping and
Prediction of Trust,” in Proc. of WISE’09, 2009.
[16] H. Guo, J. Huai, Y. Li, and T. Deng, “KAF: Kalman Filter Based Adaptive
Maintenance for Dependability of Composite Services,” in Proc. of CAiSE’08, 2008.
[17] T. Dillon, C. Wu, and E. Chang, “Cloud Computing: Issues and Challenges,” in
Proc. of AINA’10, 2010.
[18] Y. Wei and M. B. Blake, “Service-oriented Computing and Cloud Computing:
Challenges and Opportunities,” Internet Computing, IEEE, vol. 14, no. 6, pp. 72–75, 2010.
APPENDIX A
A1. SNAPSHOTS:
1. REGISTRATION MODULE:
2. Login Module
3. VIEW THE ATTACKERS CONTENTS
4. SYBIL ATTACK DETECTION
5. VIEW USER ON SERVICE
6. FIND THE REPUTATION OF CLOUD
7. FEEDBACK ABOUT THE CLOUD
8. UPLOAD THE FILE
9. LISTING ALL THE VIRTUAL MACHINES CLOUD
[Link] ALL THE USERS
[Link] ATTACK DETECTION
[Link] POSITIVE FEEDBACK
13. LIST OF NEGATIVE FEEDBACK
APPENDIX B (ABBREVATIONS)
1. TM = Trust Management
2. TMS = Trust Management Service
3. CSP = Cloud Service Providers
4. DFD = Data Flow Diagram
5. SLA = Service Level Agreement
6. TaaS = Trust as a Service
7. SRS = Software Requirement specification
8. CPU = Central Processing Unit
9. I/O = Input Output
10. GUI = Graphical User Interface
11. HTML = Hyper Text Markup Language
12. JSP = Java Server Page
13. DB = Data Base
14. IDM = Identity Management Service