Towards Model-Based Security Assessment of Cloud Applications

被引:0
|
作者
Casola, Valentina [1 ]
De Benedictis, Alessandra [1 ]
Nardone, Roberto [1 ]
机构
[1] Univ Napoli Federico II, Dept Elect Engn & Informat Technol, Naples, Italy
基金
欧盟地平线“2020”;
关键词
Model-based security assessment; Secure cloud applications; Cloud security; SYSTEMS;
D O I
10.1007/978-3-319-57186-7_56
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Security issues are still posing limitations to the full exploitation of the potential of the cloud computing paradigm, and cloud developers are more and more required to take security into account from the very beginning of the development process. Unfortunately, the application of classical security best practices may be not enough due to the involvement of cloud services provided by third-parties and out of the control of the developer. In this paper, to overcome this issue, we introduce and discuss a model-based process for the security assessment of cloud applications. In particular, we suggest a complete process that can be executed within the lifecycle of a cloud application, from the requirement elicitation up to the validation (both static and dynamic through the generation and execution of suitable test cases) of the final deployment against security requirements. In this work, we sketch the process main phases and illustrate the high-level modelling languages that have been defined to describe an application at different levels of abstraction and to formalize both security requirements of applications and security features offered by existing cloud services. A running example involving the assessment of a simple yet realistic cloud application is used throughout the paper to better illustrate the proposal and to demonstrate its feasibility and effectiveness.
引用
收藏
页码:773 / 785
页数:13
相关论文
共 50 条
  • [1] Towards a Model-Based Execution-Ware for Deploying Multi-cloud Applications
    Baur, Daniel
    Wesner, Stefan
    Domaschka, Joerg
    [J]. ADVANCES IN SERVICE-ORIENTED AND CLOUD COMPUTING, 2015, 508 : 124 - 138
  • [2] A Model-Based Scalability Optimization Methodology for Cloud Applications
    Lin, Jia-Chun
    Mauro, Jacopo
    Rost, Thomas Brox
    Yu, Ingrid Chieh
    [J]. 2017 IEEE 7TH INTERNATIONAL SYMPOSIUM ON CLOUD AND SERVICE COMPUTING (SC2 2017), 2017, : 163 - 170
  • [3] Towards a unified model-based safety assessment
    Peikenkamp, Thomas
    Cavallo, Antonella
    Valacca, Laura
    Boede, Eckard
    Pretzer, Matthias
    Hahn, E. Moritz
    [J]. COMPUTER SAFETY, RELIABILTIY, AND SECURITY, PROCEEDINGS, 2006, 4166 : 275 - 288
  • [4] A cloud model-based approach for water quality assessment
    Wang, Dong
    Liu, Dengfeng
    Ding, Hao
    Singh, Vijay P.
    Wang, Yuankun
    Zeng, Xiankui
    Wu, Jichun
    Wang, Lachun
    [J]. ENVIRONMENTAL RESEARCH, 2016, 148 : 24 - 35
  • [5] Study on Model-Based Security Assessment of Information Systems
    Li, Xiangdong
    Han, Xinchao
    Zheng, Qiusheng
    [J]. COMPUTING AND INTELLIGENT SYSTEMS, PT III, 2011, 233 : 401 - 406
  • [6] Study on Model-based Security Assessment of Information Systems
    Li, Xiangdong
    Han, Xinchao
    Zheng, Qiusheng
    [J]. 2010 SECOND INTERNATIONAL CONFERENCE ON E-LEARNING, E-BUSINESS, ENTERPRISE INFORMATION SYSTEMS, AND E-GOVERNMENT (EEEE 2010), VOL I, 2010, : 289 - 292
  • [7] Model-based risk assessment to improve enterprise security
    Aagedal, JO
    den Braber, F
    Dimitrakos, T
    Gran, BA
    Raptis, D
    Stolen, K
    [J]. SIXTH INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE, PROCEEDINGS, 2002, : 51 - 62
  • [8] Towards Language Support for Model-based Security Policy Engineering
    Amthor, Peter
    Schlegel, Marius
    [J]. PROCEEDINGS OF THE 17TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS (SECRYPT), VOL 1, 2020, : 513 - 521
  • [9] A Model-Based Systems Engineering Plugin for Cloud Security Architecture Design
    Yuri Gil Dantas
    Vivek Nigam
    Ulrich Schöpp
    [J]. SN Computer Science, 5 (5)
  • [10] Privacy preserving model-based authentication and data security in cloud computing
    Pawar, Ankush Balaram
    Ghumbre, Shashikant U.
    Jogdand, Rashmi M.
    [J]. INTERNATIONAL JOURNAL OF PERVASIVE COMPUTING AND COMMUNICATIONS, 2023, 19 (02) : 173 - 190