SpiralSRA: A Threat-Specific Security Risk Assessment Framework for the Cloud

被引:3
|
作者
Nhlabatsi, Armstrong [1 ]
Hong, Jin B. [2 ]
Kim, Dong Seong [3 ]
Fernandez, Rachael [1 ]
Fetais, Noora [1 ]
Khan, Khaled M. [1 ]
机构
[1] Qatar Univ, KINDI Ctr, Collage Engn, Doha, Qatar
[2] Univ Western Australia, Dept Comp Sci & Software Engn, Nedlands, WA, Australia
[3] Univ Canterbury, Dept Comp Sci & Software Engn, Christchurch, New Zealand
关键词
REQUIREMENTS; MANAGEMENT;
D O I
10.1109/QRS.2018.00049
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Conventional security risk assessment approaches for cloud infrastructures do not explicitly consider risk with respect to specific threats. This is a challenge for a cloud provider because it may apply the same risk assessment approach in assessing the risk of all of its clients. In practice, the threats faced by each client may vary depending on their security requirements. The cloud provider may also apply generic mitigation strategies that are not guaranteed to be effective in thwarting specific threats for different clients. This paper proposes a threat-specific risk assessment framework which evaluates the security risk with respect to specific threats by considering only those threats that are relevant to a particular cloud client. The risk assessment process is divided into three phases which have inter-related activities arranged in a spiral. An application of the framework to a cloud deployment case study shows that considering risk with respect to specific threats leads to a more accurate quantification of security risk. Although our framework is motivated by security risk assessment challenges in the cloud it can be applied in any network environment.
引用
收藏
页码:367 / 374
页数:8
相关论文
共 50 条
  • [1] Threat-Specific Security Risk Evaluation in the Cloud
    Roobini, M. S.
    TejaSatyanrayana, B.
    SaiVenkataGirish, B.
    Sridevi, N.
    Pothumani, S.
    2024 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATION AND APPLIED INFORMATICS, ACCAI 2024, 2024,
  • [2] Threat-Specific Security Risk Evaluation in the Cloud
    Nhlabatsi, Armstrong
    Hong, Jin B.
    Kim, Dong Seong
    Fernandez, Rachael
    Hussein, Alaa
    Fetais, Noora
    Khan, Khaled M.
    IEEE TRANSACTIONS ON CLOUD COMPUTING, 2021, 9 (02) : 793 - 806
  • [3] ThreatRiskEvaluator: A Tool for Assessing Threat-Specific Security Risks in the Cloud
    Nhlabatsi, Armstrong
    Hussein, Alaa
    Fernandez, Rachael
    Fetais, Noora
    Hong, Jin
    Kim, DongSeong
    Khan, Khaled M.
    2019 INTERNATIONAL CONFERENCE ON CYBER SECURITY FOR EMERGING TECHNOLOGIES (CSET), 2019,
  • [4] Security risk assessment framework for cloud computing environments
    Albakri, Sameer Hasan
    Shanmugam, Bharanidharan
    Samy, Ganthan Narayana
    Idris, Norbik Bashah
    Ahmed, Azuan
    SECURITY AND COMMUNICATION NETWORKS, 2014, 7 (11) : 2114 - 2124
  • [5] Cyber Security Risk Assessment Framework for Cloud Customer and Service Provider
    Kumari, N. Sujata
    Vurukonda, Naresh
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (12) : 683 - 697
  • [6] Security and Risk Assessment in the Cloud
    Madria, Sanjay K.
    COMPUTER, 2016, 49 (09) : 110 - 113
  • [7] Centralized gaze as a threat-specific component of defensive states in humans
    Merscher, Alma-Sophia
    Gamer, Matthias
    JOURNAL OF NEURAL TRANSMISSION, 2021, 128 (11) : 1780 - 1780
  • [8] Application design phase risk assessment framework using cloud security domains
    Sen, Amartya
    Madria, Sanjay
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2020, 55
  • [9] Risk assessment: Perchlorate as a national security threat
    Briggs, Chad M.
    IEEE TECHNOLOGY AND SOCIETY MAGAZINE, 2008, 27 (03) : 19 - 24
  • [10] Security Risk Assessment of Cloud Carrier
    Lenkala, Swetha Reddy
    Shetty, Sachin
    Xiong, Kaiqi
    PROCEEDINGS OF THE 2013 13TH IEEE/ACM INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND GRID COMPUTING (CCGRID 2013), 2013, : 442 - 449