SpiralSRA: A Threat-Specific Security Risk Assessment Framework for the Cloud

被引:3
|
作者
Nhlabatsi, Armstrong [1 ]
Hong, Jin B. [2 ]
Kim, Dong Seong [3 ]
Fernandez, Rachael [1 ]
Fetais, Noora [1 ]
Khan, Khaled M. [1 ]
机构
[1] Qatar Univ, KINDI Ctr, Collage Engn, Doha, Qatar
[2] Univ Western Australia, Dept Comp Sci & Software Engn, Nedlands, WA, Australia
[3] Univ Canterbury, Dept Comp Sci & Software Engn, Christchurch, New Zealand
关键词
REQUIREMENTS; MANAGEMENT;
D O I
10.1109/QRS.2018.00049
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Conventional security risk assessment approaches for cloud infrastructures do not explicitly consider risk with respect to specific threats. This is a challenge for a cloud provider because it may apply the same risk assessment approach in assessing the risk of all of its clients. In practice, the threats faced by each client may vary depending on their security requirements. The cloud provider may also apply generic mitigation strategies that are not guaranteed to be effective in thwarting specific threats for different clients. This paper proposes a threat-specific risk assessment framework which evaluates the security risk with respect to specific threats by considering only those threats that are relevant to a particular cloud client. The risk assessment process is divided into three phases which have inter-related activities arranged in a spiral. An application of the framework to a cloud deployment case study shows that considering risk with respect to specific threats leads to a more accurate quantification of security risk. Although our framework is motivated by security risk assessment challenges in the cloud it can be applied in any network environment.
引用
收藏
页码:367 / 374
页数:8
相关论文
共 50 条
  • [41] Risk assessment of complex information system security based on threat propagation
    Shi, Z. (shizz@ics.ict.ac.cn), 1600, Tsinghua University (54):
  • [42] Global Health Security Risk Assessment in the Biological Threat Reduction Program
    Kharaishvili, Nino
    Hudson, Toni-Marie L.
    Kannan, Jaya K.
    Ettenger, Vera
    Mirje, Seema
    HEALTH SECURITY, 2020, 18 (03) : 177 - 185
  • [43] A Novel Threat and Risk Assessment Mechanism for Security Controls in Service Management
    Wang, Ping
    Chao, Kuo-Ming
    Lo, Chi-Chun
    2013 IEEE 10TH INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE), 2013, : 337 - 344
  • [44] Threat-oriented security framework in risk management using multiagent system
    Bedi, Punam
    Gandotra, Vandana
    Singhal, Archana
    Narang, Himanshi
    Sharma, Sumit
    SOFTWARE-PRACTICE & EXPERIENCE, 2013, 43 (09): : 1013 - 1038
  • [45] Security Assessment Framework for Multi-tenant Cloud with Nested Virtualization
    Mjihil, Oussama
    Kim, Dong Seong
    Haqiq, Abdelkrim
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2016, 11 (05): : 283 - 292
  • [46] Security Assessment Framework for Multi-tenant Cloud with Nested Virtualization
    Mjihil, Oussama
    Kim, Dong Seong
    Haqiq, Abdelkrim
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2016, 11 (02): : 87 - 96
  • [47] Cloud Security Automation Framework
    Tunc, Cihan
    Hariri, Salim
    Merzouki, Mheni
    Mahmoudi, Charif
    de Vaulx, Frederic J.
    Chbili, Jaafar
    Bohn, Robert
    Battou, Abdella
    2017 IEEE 2ND INTERNATIONAL WORKSHOPS ON FOUNDATIONS AND APPLICATIONS OF SELF* SYSTEMS (FAS*W), 2017, : 307 - 312
  • [48] A Framework for Cloud Security Audit
    Ismail, Umar Mukhtar
    Islam, Shareeful
    Mouratidis, Haralambus
    GLOBAL SECURITY, SAFETY AND SUSTAINABILITY: TOMORROW'S CHALLENGES OF CYBER SECURITY, ICGS3 2015, 2015, 534 : 296 - 309
  • [49] Toward a Framework for Cloud Security
    Brock, Michael
    Goscinski, Andrzej
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, PT 2, PROCEEDINGS, 2010, 6082 : 254 - 263
  • [50] A Framework for Cloud Data Security
    Grover, Ankit
    Kaur, Banpreet
    2016 IEEE INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND AUTOMATION (ICCCA), 2016, : 1199 - 1203