首页> 外文会议>2012 IEEE Eighth World Congress on Services >SecAgreement: Advancing Security Risk Calculations in Cloud Services
【24h】

SecAgreement: Advancing Security Risk Calculations in Cloud Services

机译:SecAgreement:推进云服务中的安全风险计算

获取原文
获取原文并翻译 | 示例

摘要

By choosing to use cloud services, organizations seek to reduce costs and maximize efficiency. For mission critical systems that must satisfy security constraints, this push to the cloud introduces risks associated with cloud service providers not implementing organizationally selected security controls or policies. As internal system details are abstracted away as part of the cloud architecture, the organization must rely on contractual obligations embedded in service level agreements (SLAs) to assess service offerings. Current SLAs focus on quality of service metrics and lack the semantics needed to express security constraints that could be used to measure risk. We create a framework, called SecAgreement (SecAg), that extends the current SLA negotiation standard, WS-Agreement, to allow security metrics to be expressed on service description terms and service level objectives. The framework enables cloud service providers to include security in their SLA offerings, increasing the likelihood that their services will be used. We define and exemplify a cloud service matchmaking algorithm to assess and rank SecAg enhanced WS-Agreements by their risk, allowing organizations to quantify risk, identify any policy compliance gaps that might exist, and as a result select the cloud services that best meet their security needs.
机译:通过选择使用云服务,组织寻求降低成本并最大化效率。对于必须满足安全性约束的关键任务系统,这种向云计算的推动带来了与云服务提供商相关联的风险,这些云服务提供商未实施组织选择的安全控制或策略。随着内部系统详细信息作为云体系结构的一部分被抽象掉,组织必须依靠嵌入在服务级别协议(SLA)中的合同义务来评估服务产品。当前的SLA专注于服务质量指标,并且缺乏表达可用于度量风险的安全约束所需的语义。我们创建了一个名为SecAgreement(SecAg)的框架,该框架扩展了当前的SLA协商标准WS-Agreement,以允许在服务描述术语和服务级别目标上表达安全性指标。该框架使云服务提供商可以在其SLA产品中包括安全性,从而增加了使用其服务的可能性。我们定义并例示了云服务匹配算法,以根据风险对SecAg增强型WS-Agreement进行评估和排名,从而使组织能够量化风险,识别可能存在的任何策略合规性差距,并因此选择最能满足其安全性的云服务需要。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号