Uppsats

Protecting Integrity of Security and Audit Trail Events using Trusted Execution Environments

Master-uppsats

Linköpings universitet/Institutionen för datavetenskap

Publicerad: 2025

Språk: Engelska

Sammanfattning

Security and audit trail events play a critical role in intrusion detection, incident response, and damage assessment following security breaches. Attackers target these logs to evade detection or remove evidence. While log protection is well-studied in traditional environments, few studies have specifically addressed the challenge within Cloud Radio Access Network (Cloud RAN) infrastructures, where logs must remain secure despite an adversary potentially having privileged access to the entire platform. This thesis investigates the feasibility of integrating Trusted Execution Environments (TEEs) into Cloud RAN products to protect symmetric keys used for generating Hash-based Message Authentication Codes (HMACs). Based on a STRIDE threat assessment, identified threats are addressed by deriving a hardware-agnostic design, implemented using the Open Enclave SDK and OpenSSL, facilitating compatibility across diverse hardware environments. The resulting proof of concept performs secure key establishment through a protocol involving remote attestation and cryptographic key provisioning. To preserve integrity, security and audit trail events are securely signed within the TEE using HMACs. Subsequently, they are sent to and verified externally by a centralized Security Information and Event Management (SIEM) system. The proof of concept was evaluated in a Kubernetes-based environment with SGX-enabled hardware, assessing its impact on container image footprint, deployment latency, and scalability. Results demonstrate that while TEE integration introduces moderate overhead, it offers significant improvements in protecting critical assets even against infrastructure-level adversaries. These findings offer actionable insights for operators aiming to enhance log integrity in cloud-native deployments exposed to high-privilege threats.

Information

Lärosäte / institution
Linköpings universitet/Institutionen för datavetenskap
Publiceringsdatum
2025
Uppsatstyp
Master-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.