Security assurance assessment methodology for hybrid clouds

被引:13
|
作者
Hudic, Aleksandar [1 ]
Smith, Paul [1 ]
Weippl, Edgar R. [2 ]
机构
[1] AIT, Donau City Str 1, A-1220 Vienna, Austria
[2] SBA Res, Favoritenstr 16, A-1040 Vienna, Austria
基金
欧盟地平线“2020”;
关键词
Assurance; Cloud computing; Security assessment; Security metric; Openstack; DATA REMNANTS; CERTIFICATION; SERVICES; SYSTEM;
D O I
10.1016/j.cose.2017.03.009
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The emergence of the cloud computing paradigm has altered the delivery models for ICT services. Unfortunately, the widespread use of the cloud has a cost, in terms of reduced transparency and control over a user's information and services. In addition, there are a number of well-understood security and privacy challenges that are specific to this environment. These drawbacks are particularly problematic to operators of critical information infrastructures that want to leverage the benefits of cloud. To improve transparency and provide assurances that measures are in place to ensure security, novel approaches to security evaluation are needed. To evaluate the security of services that are deployed in the cloud requires an evaluation of complex multi-layered systems and services, including their interdependencies. This is a challenging task that involves significant effort, in terms of both computational and human resources. With these challenges in mind, we propose a novel security assessment methodology for analysing the security of critical services that are deployed in cloud environments. Our methodology offers flexibility, in that tailored policy-driven security assessments can be defined based on a user's requirements, relevant standards, policies, and guidelines. We have implemented and evaluated a system that supports online assessments using our methodology, which acquires and processes large volumes of security-related data without affecting the performance of the services in a cloud environment. (C) 2017 Published by Elsevier Ltd.
引用
收藏
页码:723 / 743
页数:21
相关论文
共 50 条
  • [1] Sustainable wireless clouds with security assurance
    Sathish K.
    Kolli K.
    Sathish, Kuppani (skuppani@gmail.com), 1600, Inderscience Publishers (14): : 146 - 159
  • [2] Hybrid security assessment methodology for web applications
    Correa R.A.
    Higuera J.R.B.
    Higuera J.B.
    Montalvo J.A.S.
    Rubio M.S.
    Alberto Magreñán Á.
    CMES - Computer Modeling in Engineering and Sciences, 2021, 126 (01): : 89 - 124
  • [3] Hybrid Security Assessment Methodology for Web Applications
    Correa, Roddy A.
    Bermejo Higuera, Juan Ramon
    Bermejo Higuera, Javier
    Sicilia Montalvo, Juan Antonio
    Sanchez Rubio, Manuel
    Alberto Magrenan, A.
    CMES-COMPUTER MODELING IN ENGINEERING & SCIENCES, 2021, 126 (01): : 89 - 124
  • [4] BASECASS: A methodology for CAPTCHAs security assurance
    Hernandez-Castro, Carlos Javier
    Barrero, David F.
    R-Moreno, Maria D.
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2021, 63
  • [5] Development of Security Software: A High Assurance Methodology
    Hardin, David
    Hiratzka, T. Douglas
    Johnson, D. Randolph
    Wagner, Lucas
    Whalen, Michael
    FORMAL METHODS AND SOFTWARE ENGINEERING, PROCEEDINGS, 2009, 5885 : 266 - 285
  • [6] A methodology for security assurance-driven system development
    Luis Vivas, Jose
    Agudo, Isaac
    Lopez, Javier
    REQUIREMENTS ENGINEERING, 2011, 16 (01) : 55 - 73
  • [7] A methodology for security assurance-driven system development
    José Luis Vivas
    Isaac Agudo
    Javier López
    Requirements Engineering, 2011, 16 : 55 - 73
  • [8] The Security Risk Assessment Methodology
    Liu, Chunlin
    Tan, Chong-Kuan
    Fang, Yea-Saen
    Lok, Tat-Seng
    INTERNATIONAL SYMPOSIUM ON SAFETY SCIENCE AND ENGINEERING IN CHINA, 2012, 2012, 43 : 600 - 609
  • [9] A Security Assessment Methodology for Critical Infrastructures
    Caselli, Marco
    Kargl, Frank
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY (CRITIS 2014), 2016, 8985 : 332 - 343
  • [10] A Formal Methodology for Procedural Security Assessment
    Weldemariam, Komminist
    Villafiorita, Adolfo
    5TH INTERNATIONAL CONFERENCE ON DIGITAL SOCIETY (ICDS 2011), 2011, : 146 - 151