首页> 外文会议>IEEE International Conference on Software Quality, Reliability, and Security >Spiral^SRA: A Threat-Specific Security Risk Assessment Framework for the Cloud
【24h】

Spiral^SRA: A Threat-Specific Security Risk Assessment Framework for the Cloud

机译:螺旋^ SRA:云的威胁特定的安全风险评估框架

获取原文

摘要

Conventional security risk assessment approaches for cloud infrastructures do not explicitly consider risk with respect to specific threats. This is a challenge for a cloud provider because it may apply the same risk assessment approach in assessing the risk of all of its clients. In practice, the threats faced by each client may vary depending on their security requirements. The cloud provider may also apply generic mitigation strategies that are not guaranteed to be effective in thwarting specific threats for different clients. This paper proposes a threat-specific risk assessment framework which evaluates the risk with respect to specific threats by considering only those threats that are relevant to a particular cloud client. The risk assessment process is divided into three phases which have inter-related activities arranged in a spiral. Application of the framework to a cloud deployment case study shows that considering risk with respect to specific threats leads to a more accurate quantification of security risk. Although our framework is motivated by risk assessment challenges in the cloud it can be applied in any network environment.
机译:云基础设施的传统安全风险评估方法没有明确考虑关于特定威胁的风险。这对云提供商来说是一个挑战,因为它可能在评估所有客户的风险时应用相同的风险评估方法。在实践中,每个客户面临的威胁可能因其安全要求而异。云提供商还可以应用不保证在挫败不同客户的特定威胁方面不保证的通用缓解策略。本文提出了一种特定于威胁的风险评估框架,通过考虑只考虑与特定云客户有关的威胁来评估关于特定威胁的风险。风险评估过程分为三个阶段,这些阶段将在螺旋中排列有关的活动。该框架在云部署案例研究中的应用表明,考虑到特定威胁的风险导致安全风险更准确的量化。虽然我们的框架受到云中的风险评估挑战的动力,但它可以应用于任何网络环境。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号