A Risk Assessment Study: Encircling Docker Container Assets on IaaS Cloud Computing Topology

被引:0
|
作者
Hersyah, Mohammad Hafiz [1 ]
Hossain, Md Delwar [1 ]
Taenaka, Yuzo [1 ]
Kadobayashi, Youki [1 ]
机构
[1] Nara Inst Sci & Technol, Div Informat Sci, Nara, Japan
关键词
Risk Assessment; docker container; Cloud Computing; Infrastructure-as-a-Service; AHP;
D O I
10.1109/CIoT57267.2023.10084910
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The articulate utilization of docker container assets in Cloud Computing is one strategic pivotal aspect of the underlying rationale for customers to conjecture on their ventures. It can be standardized under the organization's viewpoints toward its purposes and objectives, given the facilities provided by a cloud service provider. IaaS (Infrastructure-as-a-Service) topology offers many opportunities, including serverless capability in a docker container through software abstraction, and magnifying customization. Techniques such as intensifying the quality of streamlined services, and uplifts productivity, become sufficient evidence of underlying equal responsibilities between provider and customer, which need to be evaluated its risks periodically to improve the resilience of containerized objects. This study contributes alternate insight concerning risk assessment methodology in a docker container environment to mitigate the risk rating and propose risk treatment recommendations for cloud providers and customers. To grasp unified security perception in analyzing assets, threats, and vulnerabilities, harnessing several methods and international standards such as the Analytical Hierarchy process, Partial Dependency, ISO 27K Family, MITRE ATT&CK, EBIOS Risk Manager, and NIST 800-30. The experiment uses a real-world threat group from MITRE ATT&CK called TeamTNT.
引用
收藏
页码:225 / 230
页数:6
相关论文
共 50 条
  • [1] Docker Container Security in Cloud Computing
    Brady, Kelly
    Moon, Seung
    Nguyen, Tuan
    Coffman, Joel
    2020 10TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC), 2020, : 975 - 980
  • [2] Research and Implementation of Mobile Cloud Computing Offloading System Based on Docker Container
    Wang Huaijun
    Tian Ling
    Li Junhuai
    Gao Zhe
    2017 10TH INTERNATIONAL SYMPOSIUM ON COMPUTATIONAL INTELLIGENCE AND DESIGN (ISCID), VOL 2, 2017, : 270 - 274
  • [3] A Study of Risk Assessment Quantification in Cloud Computing
    Tanimoto, Shigeaki
    Sato, Ryota
    Kato, Kazuhiko
    Iwashita, Motoi
    Seki, Yoshiaki
    Sato, Hiroyuki
    Kanai, Atsushi
    2014 17TH INTERNATIONAL CONFERENCE ON NETWORK-BASED INFORMATION SYSTEMS (NBIS 2014), 2014, : 424 - 429
  • [4] A study of risk assessment quantification in cloud computing
    Tanimoto, Shigeaki
    Sato, Ryota
    Kato, Kazuhiko
    Iwashita, Motoi
    Seki, Yoshiaki
    Sato, Hiroyuki
    Kanai, Atsushi
    Proceedings - 2014 International Conference on Network-Based Information Systems, NBiS 2014, 2014, : 426 - 431
  • [5] Longitudinal risk-based security assessment of docker software container images
    Mills, Alan
    White, Jonathan
    Legg, Phil
    COMPUTERS & SECURITY, 2023, 135
  • [6] A Study, Analysis and deep dive on Cloud PAAS security in terms of Docker Container security
    Manu, A. R.
    Patel, Jitendra Kumar
    Akhtar, Shakil
    Agrawal, V. K.
    Murthy, K. N. Bala Subramanya
    PROCEEDINGS OF IEEE INTERNATIONAL CONFERENCE ON CIRCUIT, POWER AND COMPUTING TECHNOLOGIES (ICCPCT 2016), 2016,
  • [7] Survey: Risk Assessment for Cloud Computing
    Drissi, S.
    Houmani, H.
    Medromi, H.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2013, 4 (12) : 143 - 148
  • [8] Cloud Computing: Towards Risk Assessment
    Chhabra, Bharat
    Taneja, Bhawna
    HIGH PERFORMANCE ARCHITECTURE AND GRID COMPUTING, 2011, 169 : 84 - +
  • [9] Cloud Computing Potability with Risk Assessment
    Chopra, A.
    Prasad, P. W. C.
    Alsadoon, Abeer
    Ali, S. H.
    Elchouemi, A.
    2016 4TH IEEE INTERNATIONAL CONFERENCE ON MOBILE CLOUD COMPUTING, SERVICES, AND ENGINEERING (MOBILECLOUD 2016), 2016, : 53 - 59
  • [10] A Risk Assessment Framework for Cloud Computing
    Djemame, Karim
    Armstrong, Django
    Guitart, Jordi
    Macias, Mario
    IEEE TRANSACTIONS ON CLOUD COMPUTING, 2016, 4 (03) : 265 - 278