SpiralSRA: A Threat-Specific Security Risk Assessment Framework for the Cloud

被引:3
|
作者
Nhlabatsi, Armstrong [1 ]
Hong, Jin B. [2 ]
Kim, Dong Seong [3 ]
Fernandez, Rachael [1 ]
Fetais, Noora [1 ]
Khan, Khaled M. [1 ]
机构
[1] Qatar Univ, KINDI Ctr, Collage Engn, Doha, Qatar
[2] Univ Western Australia, Dept Comp Sci & Software Engn, Nedlands, WA, Australia
[3] Univ Canterbury, Dept Comp Sci & Software Engn, Christchurch, New Zealand
关键词
REQUIREMENTS; MANAGEMENT;
D O I
10.1109/QRS.2018.00049
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Conventional security risk assessment approaches for cloud infrastructures do not explicitly consider risk with respect to specific threats. This is a challenge for a cloud provider because it may apply the same risk assessment approach in assessing the risk of all of its clients. In practice, the threats faced by each client may vary depending on their security requirements. The cloud provider may also apply generic mitigation strategies that are not guaranteed to be effective in thwarting specific threats for different clients. This paper proposes a threat-specific risk assessment framework which evaluates the security risk with respect to specific threats by considering only those threats that are relevant to a particular cloud client. The risk assessment process is divided into three phases which have inter-related activities arranged in a spiral. An application of the framework to a cloud deployment case study shows that considering risk with respect to specific threats leads to a more accurate quantification of security risk. Although our framework is motivated by security risk assessment challenges in the cloud it can be applied in any network environment.
引用
收藏
页码:367 / 374
页数:8
相关论文
共 50 条
  • [21] Children With Fragile X Syndrome Display Threat-Specific Biases Toward Emotion
    Burris, Jessica L.
    Barry-Anwar, Ryan A.
    Sims, Riley N.
    Hagerman, Randi J.
    Tassone, Flora
    Rivera, Susan M.
    BIOLOGICAL PSYCHIATRY-COGNITIVE NEUROSCIENCE AND NEUROIMAGING, 2017, 2 (06) : 487 - 492
  • [22] ERP correlates of attentional processing in spider fear: evidence of threat-specific hypervigilance
    Venetacci, Rebecca
    Johnstone, Amber
    Kirkby, Kenneth C.
    Matthews, Allison
    COGNITION & EMOTION, 2018, 32 (03) : 437 - 449
  • [23] A Security Assessment Framework and Selection Method for Outsourcing Cloud Service
    Liu, Xiaochen
    Xia, Chunhe
    Cao, Jiajin
    Gao, Jinghua
    Wei, Zhao
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2014, 8 (06): : 375 - 388
  • [24] Antipredator Behavior in Desmognathus ochrophaeus: Threat-Specific Responses to Chemical Stimuli in a Foraging Context
    Johnson, Elyse C.
    Sullivan, Aaron M.
    ETHOLOGY, 2014, 120 (07) : 672 - 680
  • [25] Oxytocinergic Modulation of Threat-Specific Amygdala Sensitization in Humans Is Critically Mediated by Serotonergic Mechanisms
    Liu, Congcong
    Lan, Chunmei
    Li, Keshuang
    Zhou, Feng
    Yao, Shuxia
    Xu, Lei
    Yang, Ning
    Zhou, Xinqi
    Yang, Jiaxin
    Yong, Xue
    Ma, Yina
    Scheele, Dirk
    Kendrick, Keith M.
    Becker, Benjamin
    BIOLOGICAL PSYCHIATRY-COGNITIVE NEUROSCIENCE AND NEUROIMAGING, 2021, 6 (11) : 1081 - 1089
  • [26] A FRAMEWORK FOR CYBER SECURITY RISK ASSESSMENT OF SHIPS
    Svilicic, Boris
    Celic, Jasmin
    Kamahara, Junzo
    Bolmsten, Johan
    19TH ANNUAL GENERAL ASSEMBLY (AGA) OF THE INTERNATIONAL ASSOCIATION OF MARITIME UNIVERSITIES (IAMU), 2018, : 21 - 28
  • [27] A Security Risk Assessment Framework for Smart Car
    Kong, Hee-Kyung
    Kim, Tae-Sung
    Hong, Myoung-Ki
    2016 10TH INTERNATIONAL CONFERENCE ON INNOVATIVE MOBILE AND INTERNET SERVICES IN UBIQUITOUS COMPUTING (IMIS), 2016, : 102 - 108
  • [28] A Security Risk Assessment Framework for the Enterprise Intranet
    Lou, Fang
    Tian, Zhi-hong
    Fu, Yun-sheng
    2016 INTERNATIONAL CONFERENCE ON ELECTRICAL ENGINEERING AND AUTOMATION (ICEEA 2016), 2016,
  • [29] Framework of probabilistic risk assessment for security and reliability
    Liu, Qisi
    Xing, Liudong
    Wang, Chaonan
    2017 IEEE SECOND INTERNATIONAL CONFERENCE ON DATA SCIENCE IN CYBERSPACE (DSC), 2017, : 619 - 624
  • [30] IT Security Risk Management: An Early Assessment Framework
    Sinclaire, Jollean K.
    Simon, Judith C.
    Campbell, Charles J.
    Wilkes, Ronald B.
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2011, 6 (04): : 248 - 261