Quantitative Reasoning about Cloud Security Using Service Level Agreements

被引:27
|
作者
Luna, Jesus [1 ,2 ]
Taha, Ahmed [1 ]
Trapero, Ruben [1 ]
Suri, Neeraj [1 ]
机构
[1] Tech Univ Darmstadt, Dept Comp Sci, D-64289 Darmstadt, Germany
[2] Cloud Secur Alliance, Edinburgh, Midlothian, Scotland
基金
欧盟地平线“2020”;
关键词
Cloud security; security metrics; security quantification; security service level agreements;
D O I
10.1109/TCC.2015.2469659
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
While the economic and technological advantages of cloud computing are apparent, its overall uptake has been limited, in part, due to the lack of security assurance and transparency on the Cloud Service Provider (CSP). Although, the recent efforts on specification of security using Service Level Agreements, also known as "Security Level Agreements" or secSLAs is a positive development multiple technical and usability issues limit the adoption of Cloud secSLA's in practice. In this paper we develop two evaluation techniques, namely QPT and QHP, for conducting the quantitative assessment and analysis of the secSLA based security level provided by CSPs with respect to a set of Cloud Customer security requirements. These proposed techniques help improve the security requirements specifications by introducing a flexible and simple methodology that allows Customers to identify and represent their specific security needs. Apart from detailing guidance on the standalone and collective use of QPT and QHP, these techniques are validated using two use case scenarios and a prototype, leveraging actual real-world CSP secSLAdata derived from the Cloud Security Alliance's Security, Trust and Assurance Registry.
引用
收藏
页码:457 / 471
页数:15
相关论文
共 50 条
  • [1] Including Security Monitoring in Cloud Service Level Agreements
    Teshome, Amir
    Rilling, Louis
    Morin, Christine
    [J]. PROCEEDINGS OF 2016 IEEE 35TH SYMPOSIUM ON RELIABLE DISTRIBUTED SYSTEMS (SRDS), 2016, : 209 - 210
  • [2] Cloud Security Service Level Agreements: Representation and Measurement
    Hubballi, Neminath
    Patel, Amey Kiran
    Meena, Amit Kumar
    Tripathi, Nikhil
    [J]. IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (IEEE INFOCOM 2019 WKSHPS), 2019, : 145 - 150
  • [3] Authentication and Authorization Interface Using Security Service Level Agreements for Accessing Cloud Services
    Bajpai, Durgesh
    Vardhan, Manu
    Kushwaha, Dharmender Singh
    [J]. CONTEMPORARY COMPUTING, 2012, 306 : 370 - 382
  • [4] Leveraging the Potential of Cloud Security Service-Level Agreements through Standards
    Luna, Jesus
    Suri, Neeraj
    Iorga, Michaela
    Karmel, Anil
    [J]. IEEE CLOUD COMPUTING, 2015, 2 (03): : 32 - 40
  • [5] Service Level Agreements for Cloud Infrastructures
    Garg, Shruti
    Misra, Anuranjan
    [J]. PROCEEDINGS OF THE 2019 6TH INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT (INDIACOM), 2019, : 276 - 279
  • [6] Using Service Level Agreements for Optimising Cloud Infrastructure Services
    Lawrence, Andy
    Djemame, Karim
    Waeldrich, Oliver
    Ziegler, Wolfgang
    Zsigri, Csilla
    [J]. TOWARDS A SERVICE-BASED INTERNET: SERVICEWAVE 2010 WORKSHOPS, 2011, 6569 : 38 - +
  • [7] Automating Cloud Service Level Agreements using Semantic Technologies
    Joshi, Karuna Pande
    Pearce, Claudia
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E 2015), 2015, : 416 - 421
  • [8] Security service level agreements: Quantifiable security for the enterprise?
    Henning, RR
    [J]. NEW SECURITY PARADIGM WORKSHOP, PROCEEDINGS, 2000, : 54 - 60
  • [9] A methodology of Assessing Security Risk of Cloud Computing in User Perspective for Security-Service-Level Agreements
    Na, Sang-Ho
    Huh, Eui-Nam
    [J]. 2014 FOURTH INTERNATIONAL CONFERENCE ON INNOVATIVE COMPUTING TECHNOLOGY (INTECH), 2014, : 87 - 92
  • [10] On Incorporating Security Parameters in Service Level Agreements
    Causevic, Aida
    Lisova, Elena
    Ashjaei, Mohammad
    Ashgar, Syed Usman
    [J]. CLOSER: PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND SERVICES SCIENCE, 2019, : 48 - 57