Quantitative Reasoning about Cloud Security Using Service Level Agreements

被引:27
|
作者
Luna, Jesus [1 ,2 ]
Taha, Ahmed [1 ]
Trapero, Ruben [1 ]
Suri, Neeraj [1 ]
机构
[1] Tech Univ Darmstadt, Dept Comp Sci, D-64289 Darmstadt, Germany
[2] Cloud Secur Alliance, Edinburgh, Midlothian, Scotland
基金
欧盟地平线“2020”;
关键词
Cloud security; security metrics; security quantification; security service level agreements;
D O I
10.1109/TCC.2015.2469659
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
While the economic and technological advantages of cloud computing are apparent, its overall uptake has been limited, in part, due to the lack of security assurance and transparency on the Cloud Service Provider (CSP). Although, the recent efforts on specification of security using Service Level Agreements, also known as "Security Level Agreements" or secSLAs is a positive development multiple technical and usability issues limit the adoption of Cloud secSLA's in practice. In this paper we develop two evaluation techniques, namely QPT and QHP, for conducting the quantitative assessment and analysis of the secSLA based security level provided by CSPs with respect to a set of Cloud Customer security requirements. These proposed techniques help improve the security requirements specifications by introducing a flexible and simple methodology that allows Customers to identify and represent their specific security needs. Apart from detailing guidance on the standalone and collective use of QPT and QHP, these techniques are validated using two use case scenarios and a prototype, leveraging actual real-world CSP secSLAdata derived from the Cloud Security Alliance's Security, Trust and Assurance Registry.
引用
收藏
页码:457 / 471
页数:15
相关论文
共 50 条
  • [41] Service Level Agreements - Legal aspects [Service level agreements - rechtliche aspekte]
    Bartsch M.
    [J]. Informatik-Spektrum, 2013, 36 (5) : 449 - 454
  • [42] Reasoning About Policies in Security-Aware Service Discovery Using Answer Set Programming
    Asuncion, Vernon
    Khan, Khaled M.
    Erradi, Abdelkarim
    Alhazbi, Saleh
    [J]. INTERNATIONAL JOURNAL OF COOPERATIVE INFORMATION SYSTEMS, 2016, 25 (01)
  • [43] Cloud Computing Brokering Service: A Trust Framework Service Level Agreements: An Analytical Study in Progress
    Khanna, Prashant
    Babu, Budida Varahala
    [J]. THIRD INTERNATIONAL CONFERENCE ON CLOUD COMPUTING, GRIDS, AND VIRTUALIZATION (CLOUD COMPUTING 2012), 2012, : 206 - 212
  • [44] Ontology-Based Security Context Reasoning for Power IoT-Cloud Security Service
    Choi, Chang
    Choi, Junho
    [J]. IEEE ACCESS, 2019, 7 : 110510 - 110517
  • [45] Requirement Analysis and Design of Service Level Integration Layer for Cloud Computing Services, to Meet Service Level Agreements and Quality of Service
    Irfan, Muhammad
    Hong, Zhu
    Qamer, Tauseef
    Hussain, Shariq
    Qureshi, Usman Ali
    [J]. JOURNAL OF COMPUTATIONAL AND THEORETICAL NANOSCIENCE, 2014, 11 (03) : 629 - 636
  • [46] Research Challenges in Managing and Using Service Level Agreements
    Rana, Omer
    Ziegler, Wolfgang
    [J]. GRIDS, P2P AND SERVICES COMPUTING, 2010, : 187 - +
  • [47] Management of Service Level Agreements for Cloud Services in IoT: A Systematic Mapping Study
    Mubeen, Saad
    Asadollah, Sara Abbaspour
    Papadopoulos, Alessandro Vittorio
    Ashjaei, Mohammad
    Pei-Breivold, Hongyu
    Behnam, Moris
    [J]. IEEE ACCESS, 2018, 6 : 30184 - 30207
  • [48] Towards Soft Computing Approaches for Formulating Viable Service Level Agreements in Cloud
    Hussain, Walayat
    Hussain, Farookh Khadeer
    Hussain, Omar Khadeer
    [J]. NEURAL INFORMATION PROCESSING, ICONIP 2015, PT IV, 2015, 9492 : 639 - 646
  • [49] Closing Service Quality Gaps Using Dynamic Service Level Agreements
    Mendes, Carlos
    da Silva, Miguel Mira
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SYSTEM MODELING AND DESIGN, 2016, 7 (02) : 48 - 71
  • [50] Smart Contracts for Service-Level Agreements in Edge-to-Cloud Computing
    Petar Kochovski
    Vlado Stankovski
    Sandi Gec
    Francescomaria Faticanti
    Marco Savi
    Domenico Siracusa
    Seungwoo Kum
    [J]. Journal of Grid Computing, 2020, 18 : 673 - 690