...
首页> 外文期刊>Computers & Security >Security assurance assessment methodology for hybrid clouds
【24h】

Security assurance assessment methodology for hybrid clouds

机译:混合云的安全保证评估方法

获取原文
获取原文并翻译 | 示例
           

摘要

The emergence of the cloud computing paradigm has altered the delivery models for ICT services. Unfortunately, the widespread use of the cloud has a cost, in terms of reduced transparency and control over a user's information and services. In addition, there are a number of well-understood security and privacy challenges that are specific to this environment. These drawbacks are particularly problematic to operators of critical information infrastructures that want to leverage the benefits of cloud. To improve transparency and provide assurances that measures are in place to ensure security, novel approaches to security evaluation are needed. To evaluate the security of services that are deployed in the cloud requires an evaluation of complex multi-layered systems and services, including their interdependencies. This is a challenging task that involves significant effort, in terms of both computational and human resources. With these challenges in mind, we propose a novel security assessment methodology for analysing the security of critical services that are deployed in cloud environments. Our methodology offers flexibility, in that tailored policy-driven security assessments can be defined based on a user's requirements, relevant standards, policies, and guidelines. We have implemented and evaluated a system that supports online assessments using our methodology, which acquires and processes large volumes of security-related data without affecting the performance of the services in a cloud environment.
机译:云计算范例的出现改变了ICT服务的交付模式。不幸的是,就降低透明度以及对用户信息和服务的控制而言,云的广泛使用需要付出一定的代价。此外,针对此环境还存在许多容易理解的安全和隐私挑战。对于希望利用云的优势的关键信息基础架构的运营商而言,这些缺点尤其成问题。为了提高透明度并确保已采取措施确保安全性,需要一种新颖的安全性评估方法。要评估部署在云中的服务的安全性,需要评估复杂的多层系统和服务,包括它们之间的相互依赖性。这是一项艰巨的任务,需要大量的人力和物力。考虑到这些挑战,我们提出了一种新颖的安全评估方法,用于分析部署在云环境中的关键服务的安全性。我们的方法提供了灵活性,因为可以基于用户的需求,相关标准,策略和准则来定义量身定制的策略驱动的安全评估。我们已经实施并评估了使用我们的方法支持在线评估的系统,该系统可以获取和处理大量与安全性相关的数据,而不会影响云环境中服务的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号