Security assurance assessment methodology for hybrid clouds

被引:13
|
作者
Hudic, Aleksandar [1 ]
Smith, Paul [1 ]
Weippl, Edgar R. [2 ]
机构
[1] AIT, Donau City Str 1, A-1220 Vienna, Austria
[2] SBA Res, Favoritenstr 16, A-1040 Vienna, Austria
基金
欧盟地平线“2020”;
关键词
Assurance; Cloud computing; Security assessment; Security metric; Openstack; DATA REMNANTS; CERTIFICATION; SERVICES; SYSTEM;
D O I
10.1016/j.cose.2017.03.009
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The emergence of the cloud computing paradigm has altered the delivery models for ICT services. Unfortunately, the widespread use of the cloud has a cost, in terms of reduced transparency and control over a user's information and services. In addition, there are a number of well-understood security and privacy challenges that are specific to this environment. These drawbacks are particularly problematic to operators of critical information infrastructures that want to leverage the benefits of cloud. To improve transparency and provide assurances that measures are in place to ensure security, novel approaches to security evaluation are needed. To evaluate the security of services that are deployed in the cloud requires an evaluation of complex multi-layered systems and services, including their interdependencies. This is a challenging task that involves significant effort, in terms of both computational and human resources. With these challenges in mind, we propose a novel security assessment methodology for analysing the security of critical services that are deployed in cloud environments. Our methodology offers flexibility, in that tailored policy-driven security assessments can be defined based on a user's requirements, relevant standards, policies, and guidelines. We have implemented and evaluated a system that supports online assessments using our methodology, which acquires and processes large volumes of security-related data without affecting the performance of the services in a cloud environment. (C) 2017 Published by Elsevier Ltd.
引用
收藏
页码:723 / 743
页数:21
相关论文
共 50 条
  • [41] A Cost-Effective Methodology Applied to Videoconference Services over Hybrid Clouds
    Javier Cerviño
    Pedro Rodríguez
    Irena Trajkovska
    Fernando Escribano
    Joaquín Salvachúa
    Mobile Networks and Applications, 2013, 18 : 103 - 109
  • [42] Hybrid Cuckoo search - ABC algorithm based Vulnerabilities mapping and Security in Clouds
    Prashanth, S. K.
    Rao, N. Sambasiva
    Kumar, C. Satya
    2016 INTERNATIONAL CONFERENCE ON ELECTRICAL, ELECTRONICS, AND OPTIMIZATION TECHNIQUES (ICEEOT), 2016, : 2569 - 2572
  • [43] CQR - A HYBRID EXPERT SYSTEM FOR SECURITY ASSESSMENT
    CHRISTIE, RD
    TALUKDAR, SN
    NIXON, JC
    IEEE TRANSACTIONS ON POWER SYSTEMS, 1990, 5 (04) : 1503 - 1509
  • [44] Harmonized Monitoring for High Assurance Clouds
    Bicaku, Ani
    Balaban, Silvia
    Tauber, Markus G.
    Hudic, Aleksandar
    Mauthe, Andreas
    Hutchison, David
    2016 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING WORKSHOP (IC2EW), 2016, : 118 - 123
  • [45] Security-aware task scheduling with deadline constraints on heterogeneous hybrid clouds
    Wang, Bo
    Wang, Changhai
    Huang, Wanwei
    Song, Ying
    Qin, Xiaoyun
    JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2021, 153 : 15 - 28
  • [46] Information-Flow Control for Building Security and Privacy Preserving Hybrid Clouds
    Shyamasundar, R. K.
    Kumar, N. V. Narendra
    Rajarajan, Muttukrishnan
    PROCEEDINGS OF 2016 IEEE 18TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS; IEEE 14TH INTERNATIONAL CONFERENCE ON SMART CITY; IEEE 2ND INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS), 2016, : 1410 - 1417
  • [47] Hybrid Clouds
    Yousif, Mazin
    IEEE CLOUD COMPUTING, 2016, 3 (01): : 6 - +
  • [48] Security risk assessment methodology for communities (RAM-C)
    Jaeger, C
    IEEE AEROSPACE AND ELECTRONIC SYSTEMS MAGAZINE, 2005, 20 (06) : 15 - 17
  • [49] Security risk assessment methodology for communities (RAM-C™)
    Jaeger, C
    PROBABILISTIC SAFETY ASSESSMENT AND MANAGEMENT, VOL 1- 6, 2004, : 1328 - 1332
  • [50] SVAPP methodology: A predictive security vulnerability assessment modeling method
    van Staalduinen, Mark Adrian
    Khan, Faisal
    Gadag, Veeresh
    JOURNAL OF LOSS PREVENTION IN THE PROCESS INDUSTRIES, 2016, 43 : 397 - 413