首页> 外文会议>International conference on current trends in theory and practice of computer science >Towards Automatic Comparison of Cloud Service Security Certifications
【24h】

Towards Automatic Comparison of Cloud Service Security Certifications

机译:致力于自动比较云服务安全认证

获取原文
获取外文期刊封面目录资料

摘要

Cloud service providers who offer services to their users traditionally signal security of their offerings through certifications based on various certification schemes. Currently, a vast number of schemes and standards exists on one side (cloud service certifications), while another large set of security requirements stemming from internal needs or laws and regulations stand on the other side (users of cloud services). Determining whether a service with an arbitrary certificate in one country fulfills requirements imposed by the user in another country is a difficult task and therefore a project (EU-SEC) was started focusing on allowing cross-border usage of cloud services. In this paper, we propose automated comparison of cloud service security certification schemes and, subsequently, security of cloud services certified using these schemes. In the presented method, we map requirements in schemes, standards, laws, and regulations into a proposed cloud service security ontology. Due to the free-form text nature of these items, we also describe a supporting method for semi-automated conversion of free text into this ontology using natural language processing. The requirements described in ontology format are then easily compared against each other. We also describe an implementation of a prototype system supporting the conversion and comparison with preliminary results on describing and comparing two well-known schemes.
机译:传统上,向用户提供服务的云服务提供商通过基于各种认证方案的认证来表示其产品的安全性。当前,一方面存在大量的计划和标准(云服务认证),而另一方面(内部又是云服务的用户)则存在另一组基于内部需求或法律法规的大量安全要求。确定一个国家/地区具有任意证书的服务是否满足另一个国家/地区用户的要求是一项艰巨的任务,因此,一个项目(EU-SEC)开始着眼于允许跨界使用云服务。在本文中,我们提出了云服务安全认证方案的自动比较,以及随后使用这些方案认证的云服务的安全性。在提出的方法中,我们将方案,标准,法律和法规中的需求映射到提议的云服务安全本体中。由于这些项目的自由格式文本性质,我们还描述了一种使用自然语言处理将自由文本半自动转换为该本体的支持方法。这样就可以轻松地将以本体格式描述的需求相互比较。我们还描述了支持转换和比较的原型系统的实现,并具有描述和比较两个著名方案的初步结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号