A broker-based framework for standardization and management of Cloud Security-SLAs

被引:29
|
作者
Halabi, Talal [1 ]
Bellaiche, Martine [1 ]
机构
[1] Ecole Polytech Montreal, Genie Informat & Genie Logiciel, Montreal, PQ, Canada
关键词
Standard Security-SLA; Service selection; Security evaluation; Security-SLA optimization; Security-SLA monitoring;
D O I
10.1016/j.cose.2018.01.019
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security is still one of the main barriers discouraging companies and businesses which deal with sensitive information and confidential data from migrating toward the Cloud. Recent efforts have tried to specify the security level of the Cloud service with the help of Security Service Level Agreements (Security-SLAs). However, Security-SLAs in their current format and with their present terms are not fully measurable and are hard to monitor. Quantification and standardization of Security-SLAs will surely speed up the Cloud adoption process and attract more customers to benefit from the advantages of Cloud computing in a more confident and secure fashion. In this paper, we propose a broker-based framework that manages the Cloud Security-SLA. We first develop a standard, quantitative, and measurable form to represent the agreement. Then we propose an evaluation and selection model that is fundamentally based on computing the adequate trade-off between the security CIA triad attributes (Confidentiality, Integrity, and Availability) in the context of a multi objective optimization problem. Simulation results show the set of Pareto-optimal solutions and how the customer can select the most suitable service provider using higher level information that is related to the nature of the service and financial cost. (C) 2018 Elsevier Ltd. All rights reserved.
引用
收藏
页码:59 / 71
页数:13
相关论文
共 50 条
  • [1] Broker-based mechanism for cloud provider selection
    Achar, Raghavendra
    Thilagam, P. Santhi
    Acharya, Shreenath
    [J]. INTERNATIONAL JOURNAL OF COMPUTATIONAL SCIENCE AND ENGINEERING, 2020, 22 (01) : 50 - 61
  • [2] A broker-based cooperative security-SLA evaluation methodology for personal cloud computing
    Na, Sang-Ho
    Huh, Eui-Nam
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (07) : 1318 - 1331
  • [3] Broker-based optimization of SLA negotiations in cloud computing
    Bharti, Priyanka
    Ranjan, Rajeev
    Prasad, Bhanu
    [J]. MULTIAGENT AND GRID SYSTEMS, 2021, 17 (02) : 179 - 195
  • [4] Broker-Based Cross-Cloud Federation Manager
    Abdo, Jacques Bou
    Demerjian, Jacques
    Chaouchi, Hakima
    Barbar, Kabalan
    Pujolle, Guy
    [J]. 2013 8TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2013, : 244 - +
  • [5] Cloud Broker-based Refundable Service on Multitenant Environment
    Hossain, Al Amin
    Shin, Young-Rok
    Lee, Seung-Jin
    Lim, Cheol-Su
    Huh, Eui-Nam
    [J]. 2013 INTERNATIONAL CONFERENCE ON ICT FOR SMART SOCIETY (ICISS): THINK ECOSYSTEM ACT CONVERGENCE, 2013, : 181 - 185
  • [6] Runtime Performance Management of Information Broker-Based Adaptive Applications
    Purhonen, Anu
    Stenudd, Sakari
    [J]. SOFTWARE ARCHITECTURE, 2011, 6903 : 203 - 206
  • [7] A broker-based framework for QoS-aware Web service composition
    Yu, T
    Lin, KJ
    [J]. 2005 IEEE International Conference on e-Technology, e-Commerce and e-Service, Proceedings, 2005, : 22 - 29
  • [8] QoS provisioning and policy management in a broker-based CR network architecture
    Bourdena, Athina
    Pallis, Evangelos
    Kormentzas, Georgios
    Skianis, Charalabos
    Mastorakis, George
    [J]. 2012 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2012,
  • [9] Per-service security SLAs for cloud security management: model and implementation
    Casola, Valentina
    De Benedictis, Alessandra
    Modic, Jolanda
    Rak, Massimiliano
    Villano, Umberto
    [J]. INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2018, 9 (02) : 128 - 138
  • [10] A framework to address inconstant user requirements in cloud SLAs management
    Halboob, Waleed
    Abbas, Haider
    Khan, Muhammad Khurram
    Khan, Farrukh Aslam
    Pasha, Maruf
    [J]. CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2015, 18 (01): : 123 - 133