...
首页> 外文期刊>Procedia Computer Science >Utilizing Third Party Auditing to Manage Trust in the Cloud
【24h】

Utilizing Third Party Auditing to Manage Trust in the Cloud

机译:利用第三方审核管理云中的信任

获取原文

摘要

Recent trends within the IT industry have led to a tectonic shift in the way organizations utilize information systems to yield maximum efficiency. Cloud computing is the cornerstone of the aforementioned paradigm permutation. Information security, however, continues to dominate discussion on how organizations can utilize the efficiency of the cloud, while simultaneously maintaining end-user privacy and trust. The advent of cloud computing has likewise brought with it a multitude of new and exciting concepts that can complicate security demands exponentially. These security demands must be met to ensure user trust. Multi-tenancy is a cloud computing concept that is at the forefront of information security concerns in the 21st century computing environment. Current Multi-tenancy models fail to provide adequate security measures by blindly multiplexing various unknown users, whose intentions can be hostile, with reputable cloud service users. In this paper, we propose a novel security auditing framework to establish the user trust by (a) allowing the cloud service users (CSUs) to provide their security preferences with the desired cloud services, (b) providing a conceptual mechanism to validate the security controls and internal security policies of cloud service providers (CSPs) published in the CSA's (Cloud Security Alliance) Security Trust and Assurance Registry (STAR) database, and (c) maintaining a database of CSPs along with their responses to the Consensus Assessments Initiative Questionnaire (CAIQ) as well as the certificates issued by the certificate authorities. Thus, our proposed framework facilitates the CSUs in choosing a trustworthy CSP by empowering them to select an appropriate security preferences and services.
机译:IT行业内的最新趋势已导致组织利用信息系统产生最大效率的方式发生了结构性转变。云计算是上述范式置换的基石。但是,信息安全继续成为有关组织如何利用云的效率同时保持最终用户隐私和信任的讨论的主导。云计算的出现同样带来了许多新颖而令人兴奋的概念,这些概念可能使安全需求呈指数级增长。必须满足这些安全要求,以确保用户信任。多租户是一种云计算概念,在21世纪计算环境中处于信息安全关注的最前沿。当前的多租户模型无法通过盲目的多路复用各种未知用户(其意图可能是敌对的)与信誉良好的云服务用户来提供适当的安全措施。在本文中,我们提出了一种新颖的安全审核框架,通过以下方式建立用户信任:(a)允许云服务用户(CSU)提供所需的云服务来提供其安全偏好,(b)提供一种概念机制来验证安全性在CSA(云安全联盟)安全信任和保证注册表(STAR)数据库中发布的云服务提供商(CSP)的控制和内部安全策略,以及(c)维护CSP数据库以及它们对共识评估倡议问卷的答复(CAIQ)以及证书颁发机构颁发的证书。因此,我们提出的框架通过授权CSU选择合适的安全首选项和服务,从而帮助他们选择可信赖的CSP。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号