A Metric-Based Approach to Assess Risk for “On Cloud” Federated Identity Management

被引:0
|
作者
Patricia Arias-Cabarcos
Florina Almenárez-Mendoza
Andrés Marín-López
Daniel Díaz-Sánchez
Rosa Sánchez-Guerrero
机构
[1] University Carlos III of Madrid,Department of Telematics Engineering
关键词
Trust management; Cloud computing; Risk assessment metrics; SAML; Federation;
D O I
暂无
中图分类号
学科分类号
摘要
The cloud computing paradigm is set to become the next explosive revolution on the Internet, but its adoption is still hindered by security problems. One of the fundamental issues is the need for better access control and identity management systems. In this context, Federated Identity Management (FIM) is identified by researchers and experts as an important security enabler, since it will play a vital role in allowing the global scalability that is required for the successful implantation of cloud technologies. However, current FIM frameworks are limited by the complexity of the underlying trust models that need to be put in place before inter-domain cooperation. Thus, the establishment of dynamic federations between the different cloud actors is still a major research challenge that remains unsolved. Here we show that risk evaluation must be considered as a key enabler in evidence-based trust management to foster collaboration between cloud providers that belong to unknown administrative domains in a secure manner. In this paper, we analyze the Federated Identity Management process and propose a taxonomy that helps in the classification of the involved risks in order to mitigate vulnerabilities and threats when decisions about collaboration are made. Moreover, a set of new metrics is defined to allow a novel form of risk quantification in these environments. Other contributions of the paper include the definition of a generic hierarchical risk aggregation system, and a descriptive use-case where the risk computation framework is applied to enhance cloud-based service provisioning.
引用
收藏
页码:513 / 533
页数:20
相关论文
共 50 条
  • [41] Reliability Analysis of Trust based Federated Identity Management in InterCloud: A Graph Coloring Approach
    Premarathne, Uthpala Subodhani
    2017 14TH IEEE ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC), 2017, : 345 - 348
  • [42] Program Code Understandability and Authenticating Code Predicting Systems: A Metric-Based Approach
    Jha, Pooja
    Patnaik, K. Sridhar
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SIGNAL, NETWORKS, COMPUTING, AND SYSTEMS (ICSNCS 2016), VOL 2, 2016, 396 : 95 - 103
  • [43] An Approach to Counteracting the Common Cyber-attacks According to the Metric-Based Model
    Geramiparvar, Mohammad Sirwan
    Modiri, Nasser
    International Journal of Computer Science and Network Security, 2016, 16 (01): : 81 - 85
  • [44] A novel parallel distance metric-based approach for diversified ranking on large graphs
    Li, Jin
    Yang, Yun
    Wang, Xiaoling
    Zhao, Zhiming
    Li, Tong
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 88 : 79 - 91
  • [45] Enhancing Federated Cloud Management with an Integrated Service Monitoring Approach
    A. Kertesz
    G. Kecskemeti
    M. Oriol
    P. Kotcauer
    S. Acs
    M. Rodríguez
    O. Mercè
    A. Cs. Marosi
    J. Marco
    X. Franch
    Journal of Grid Computing, 2013, 11 : 699 - 720
  • [46] Enhancing Federated Cloud Management with an Integrated Service Monitoring Approach
    Kertesz, A.
    Kecskemeti, G.
    Oriol, M.
    Kotcauer, P.
    Acs, S.
    Rodriguez, M.
    Merce, O.
    Marosi, A. Cs
    Marco, J.
    Franch, X.
    JOURNAL OF GRID COMPUTING, 2013, 11 (04) : 699 - 720
  • [47] An Approach for Assessing Similarity Metrics Used in Metric-based Clone Detection Techniques
    Shawky, Doaa M.
    Ali, Ahmed F.
    PROCEEDINGS 2010 3RD IEEE INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND INFORMATION TECHNOLOGY, (ICCSIT 2010), VOL 1, 2010, : 580 - 584
  • [48] An Efficient Metric-Based Approach for Static Use-After-Free Detection
    Wei, Haolai
    Chen, Liwei
    Nie, Xiaofan
    Zhang, Zhijie
    Zhang, Yuantong
    Shi, Gang
    2022 IEEE INTL CONF ON PARALLEL & DISTRIBUTED PROCESSING WITH APPLICATIONS, BIG DATA & CLOUD COMPUTING, SUSTAINABLE COMPUTING & COMMUNICATIONS, SOCIAL COMPUTING & NETWORKING, ISPA/BDCLOUD/SOCIALCOM/SUSTAINCOM, 2022, : 58 - 65
  • [49] An integrated approach to federated identity and privilege management in open systems
    Bhatti, Rafae
    Bertino, Elisa
    Ghafoor, Arif
    COMMUNICATIONS OF THE ACM, 2007, 50 (02) : 81 - 87
  • [50] An Ontology-based Architecture for Federated Identity Management
    Layouni, Farah
    Pollet, Yann
    2009 INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS, 2009, : 162 - 166