首页> 外文OA文献 >A Trust-aware framework for evaluating security controls of service providers in cloud marketplaces
【2h】

A Trust-aware framework for evaluating security controls of service providers in cloud marketplaces

机译:用于评估云市场中服务提供商的安全控制的信任感知框架

摘要

Trustworthy selection of cloud services has become a significant issue in emerging cloud marketplaces. As a consequence, the Cloud Security Alliance (CSA) has formulated a self-assessment framework for cloud providers to publish their cloud platform's security controls and capabilities. This framework enables consumers to select a cloud service based on the capabilities and controls published by the providers. However, a fundamental question that arises is, how can consumers trust that the security controls are satisfied as claimed by the providers and are compliant with consumers' requirements. This paper proposes a trust-aware framework to verify and evaluate these security controls considering consumers' requirements. First, we model the security controls in the form of trust properties. Then, we introduce a taxonomy of these properties based on their semantics and identify the authorities who can validate the properties. The taxonomy of these properties is the basis of trust formalisation in our proposed framework. The framework rests on the notion of hybrid trust that combines hard and soft trust mechanisms for verifying the trust properties. Furthermore, a decision model is proposed as an integral part of the framework in order to empower consumers to determine trustworthiness of cloud providers. Finally, we demonstrate that the proposed trust-aware security evaluation framework could be potentially useful in practice for consumers to determine trustworthy cloud providers in a competitive marketplace.
机译:在新兴的云市场中,对云服务的可信赖选择已成为一个重要问题。因此,云安全联盟(CSA)为云提供商制定了自我评估框架,以发布其云平台的安全控制和功能。该框架使消费者可以根据提供商提供的功能和控制来选择云服务。但是,出现的一个基本问题是,消费者如何才能相信提供商所要求的安全控制得到满足并符合消费者的要求。本文提出了一个信任感知框架,以考虑消费者的需求来验证和评估这些安全控制。首先,我们以信任属性的形式对安全控件进行建模。然后,我们根据这些属性的语义介绍它们的分类法,并确定可以验证这些属性的权威。这些属性的分类法是我们提出的框架中信任形式化的基础。该框架基于混合信任的概念,该概念结合了用于验证信任属性的硬和软信任机制。此外,决策模型被提议作为框架的组成部分,以使消费者能够确定云提供商的可信度。最后,我们证明了所提出的信任感知安全评估框架在实践中对于消费者在竞争性市场中确定可信赖的云提供商方面可能很有用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号