Security assurance assessment methodology for hybrid clouds

被引:13
|
作者
Hudic, Aleksandar [1 ]
Smith, Paul [1 ]
Weippl, Edgar R. [2 ]
机构
[1] AIT, Donau City Str 1, A-1220 Vienna, Austria
[2] SBA Res, Favoritenstr 16, A-1040 Vienna, Austria
基金
欧盟地平线“2020”;
关键词
Assurance; Cloud computing; Security assessment; Security metric; Openstack; DATA REMNANTS; CERTIFICATION; SERVICES; SYSTEM;
D O I
10.1016/j.cose.2017.03.009
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The emergence of the cloud computing paradigm has altered the delivery models for ICT services. Unfortunately, the widespread use of the cloud has a cost, in terms of reduced transparency and control over a user's information and services. In addition, there are a number of well-understood security and privacy challenges that are specific to this environment. These drawbacks are particularly problematic to operators of critical information infrastructures that want to leverage the benefits of cloud. To improve transparency and provide assurances that measures are in place to ensure security, novel approaches to security evaluation are needed. To evaluate the security of services that are deployed in the cloud requires an evaluation of complex multi-layered systems and services, including their interdependencies. This is a challenging task that involves significant effort, in terms of both computational and human resources. With these challenges in mind, we propose a novel security assessment methodology for analysing the security of critical services that are deployed in cloud environments. Our methodology offers flexibility, in that tailored policy-driven security assessments can be defined based on a user's requirements, relevant standards, policies, and guidelines. We have implemented and evaluated a system that supports online assessments using our methodology, which acquires and processes large volumes of security-related data without affecting the performance of the services in a cloud environment. (C) 2017 Published by Elsevier Ltd.
引用
收藏
页码:723 / 743
页数:21
相关论文
共 50 条
  • [21] Security in the clouds
    Pritchard, Stephen
    Infosecurity, 2009, 6 (01) : 34 - 37
  • [22] Efficient Public Verifiability and Data Dynamics for Storage Security in Hybrid Clouds
    Aman, Amish Kumar
    Prakash, Vijay
    2013 4TH IEEE INTERNATIONAL CONFERENCE ON COMPUTER & COMMUNICATION TECHNOLOGY (ICCCT), 2013, : 28 - 33
  • [23] New security architecture using hybrid IDS for virtual private clouds
    Elmaaradi, Ayoub
    Lyhyaoui, Abdelouahid
    Chairi, Ikram
    2019 THIRD INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTING IN DATA SCIENCES (ICDS 2019), 2019,
  • [24] METHODOLOGY FOR AN ECONOMIC-ASSESSMENT OF A RELIABILITY ASSURANCE WARRANTY PROGRAM (RAWP)
    SHUPE, RH
    DRIESSNACK, J
    PROCEEDINGS ANNUAL RELIABILITY AND MAINTAINABILITY SYMPOSIUM, 1991, (SYM): : 345 - 351
  • [25] A Methodology for Dynamic Security Risks Assessment in Interconnected IT Systems
    Fayyad, Seraj
    Alkhatib, Ahmad
    Abdel-Fattah, Farhan
    Almimi, Hani
    JOURNAL OF COMMUNICATIONS SOFTWARE AND SYSTEMS, 2024, 20 (01) : 13 - 22
  • [26] Security Risk Assessment Methodology for the petroleum and petrochemical industries
    Moore, David A.
    JOURNAL OF LOSS PREVENTION IN THE PROCESS INDUSTRIES, 2013, 26 (06) : 1685 - 1689
  • [27] Research on Information Security Asset Value Assessment Methodology
    Yang, Xueqin
    Yang, Peng
    Lin, Honggang
    CYBER SECURITY, CNCERT 2022, 2022, 1699 : 162 - 174
  • [28] Information Security Maturity Level: A Fast Assessment Methodology
    Monteiro, Sergio
    Magalhaes, Joao Paulo
    AMBIENT INTELLIGENCE- SOFTWARE AND APPLICATIONS- 8TH INTERNATIONAL SYMPOSIUM ON AMBIENT INTELLIGENCE (ISAMI 2017), 2017, 615 : 269 - 277
  • [29] Steady security assessment using linear programming methodology
    Shukla, M
    Sekar, A
    PROCEEDINGS OF THE THIRTY-SIXTH SOUTHEASTERN SYMPOSIUM ON SYSTEM THEORY, 2004, : 141 - 144
  • [30] A Formal Methodology for Enterprise Information Security Risk Assessment
    Bhattacharjee, Jaya
    Sengupta, Anirban
    Mazumdar, Chandan
    2013 INTERNATIONAL CONFERENCE ON RISKS AND SECURITY OF INTERNET AND SYSTEMS (CRISIS), 2013,