Modeling security requirements for cloud-based system development

被引:19
|
作者
Ficco, Massimo [1 ]
Palmieri, Francesco [1 ]
Castiglione, Aniello [2 ]
机构
[1] Univ Naples 2, Dept Ind & Informat Engn, Aversa, CE, Italy
[2] Univ Salerno, Dept Comp Sci, Fisciano, SA, Italy
来源
关键词
cloud computing; security; modeling; cloud applications; UML-based metamodel; ISSUES;
D O I
10.1002/cpe.3402
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The Cloud Computing paradigm provides a new model for the more flexible utilization of computing and storage services. However, such enhanced flexibility, which implies outsourcing the data and business applications to a third party, may introduce critical security issues. Therefore, there is a clear necessity of new security paradigms able to face all the problems introduced by the cloud approach. Although, in the last years, several solutions have been proposed, the implementation of secure cloud applications and services is still a complex and far from consolidated task. Starting from these considerations, this work fosters the development of a methodology that considers security concerns as an integral part of cloud-based applications design and implementation. Accordingly, we present a set of stereotypes that defines a vocabulary for annotating Unified Modeling Language based models with information relevant for integrating the specification of security requirements into cloud architectures. This approach can be used to significantly improve productivity and overall success in the development of secure distributed cloud applications and systems. Copyright (c) 2014 John Wiley & Sons, Ltd.
引用
收藏
页码:2107 / 2124
页数:18
相关论文
共 50 条
  • [1] Security Requirements for Cloud-based C4I Security Architecture
    Koo, Jahoon
    Kim, Young-Gab
    Lee, Sang-Hoon
    [J]. 2019 INTERNATIONAL CONFERENCE ON PLATFORM TECHNOLOGY AND SERVICE (PLATCON), 2019, : 131 - 134
  • [2] A security framework for cloud-based video surveillance system
    Mohammad A. Alsmirat
    Islam Obaidat
    Yaser Jararweh
    Mohammed Al-Saleh
    [J]. Multimedia Tools and Applications, 2017, 76 : 22787 - 22802
  • [3] A Security Framework for Cloud-Based Web Crawling System
    Li Yan
    Zhao Li
    Liu Xin-ran
    Zhang Peng
    [J]. 2014 11TH WEB INFORMATION SYSTEM AND APPLICATION CONFERENCE (WISA), 2014, : 101 - 104
  • [4] A CLOUD-BASED SYSTEM FOR ENHANCING SECURITY OF ANDROID DEVICES
    Qian, Han
    Wen, Qiaoyan
    [J]. 2012 IEEE 2ND INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND INTELLIGENT SYSTEMS (CCIS) VOLS 1-3, 2012, : 245 - 249
  • [5] Security Design and Implementation of the Cloud-based Online System
    Chen, Wei
    Shang, Yuting
    [J]. 2016 3RD INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY FOR EDUCATION (ICTE 2016), 2016, : 233 - 236
  • [6] A security framework for cloud-based video surveillance system
    Alsmirat, Mohammad A.
    Obaidat, Islam
    Jararweh, Yaser
    Al-Saleh, Mohammed
    [J]. MULTIMEDIA TOOLS AND APPLICATIONS, 2017, 76 (21) : 22787 - 22802
  • [7] CBSS: Cloud-Based Security System with Interface to Network Security Functions
    Jeong, Jaehoon
    Lingga, Patrick
    [J]. 2023 FOURTEENTH INTERNATIONAL CONFERENCE ON MOBILE COMPUTING AND UBIQUITOUS NETWORK, ICMU, 2023,
  • [8] Cloud Computing Framework for e-Health Security Requirements and Security Policy Rules Case Study: A European Cloud-Based Health System
    Georgiou, Dimitra
    Lambrinoudakis, Costas
    [J]. TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS, TRUSTBUS 2020, 2020, 12395 : 17 - 31
  • [9] Requirements for a cloud-based Control System interacting with Soft Bodies
    Tomzik, David A.
    Xu, Xun W.
    [J]. 2017 24TH INTERNATIONAL CONFERENCE ON MECHATRONICS AND MACHINE VISION IN PRACTICE (M2VIP), 2017, : 83 - 87
  • [10] Analysis of the Security and Privacy Requirements of Cloud-Based Electronic Health Records Systems
    Rodrigues, Joel J. P. C.
    de la Torre, Isabel
    Fernandez, Gonzalo
    Lopez-Coronado, Miguel
    [J]. JOURNAL OF MEDICAL INTERNET RESEARCH, 2013, 15 (08)