arrow
返回

Application design phase risk assessment framework using cloud security domains

delete2020-12-01
delete7
PRE
AI
A
Amartya Sen
S
Sanjay Madria *
DOI:10.1016/j.jisa.2020.102617delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Security risk assessment is done to identify the vulnerabilities of a client's application and develop strong security measures within budgetary constraints. However, while migrating to the Cloud platform, a generic notion of their publicly available security policies make it challenging for clients to assess the security threats solely relevant to their applications. Additionally, traditional risk assessment techniques cannot address these challenges as they neither consider cloud security domains as assessment criteria nor identifies critical system resources that need to be protected in the likelihood of a successful attack. In order to address these challenges, this paper presents a risk assessment framework for clients' applications that is characterized by the inclusion of cloud security metrics to perform risk assessment during the design phase of an application by incorporating the techniques of cloud misuse patterns. It also helps improve the security requirements phase that precedes risk assessment, by illustrating clients how different attack scenarios can spread through the applications by using the concepts of percolation centrality and probabilistic state transition diagrams. One of the key findings this work address is how to systematically gain a distinction between multiple system resources belonging to the same security defense priority level.
Keyword:
Cloud computing
Cloud migration
Security risk assessment
Software development lifecycle
Misuse patterns
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Journal of Information Security and Applications 封面图
Journal of Information Security and Applications
IF:
3.7
论文数:
2.0K
被引数:
4.9K

机构

O
Oakland University
学者数:
3.7K
论文数: 3.0K
被引数: 2.7K
University of Missouri System 封面图
University of Missouri System
学者数:
3.0W
论文数: 2.7W
被引数: 75
引用论文

引用论文

Antibodies against metal chelates
err1985-07-18
err0
PREAI
errDayton T. Reardan; Claude F. Meares; David A. Goodwin; Maureen McTigue; Gary S. David; Mary R. Stone; Julia P. Leung; Richard M. Bartholomew; James M. Frincke
err分享
err收藏
A modified epidemiological model for computer viruses
err2009-07-01
err186
PREAI
errPiqueira, Jose Roberto C.; Araujo, Vanessa O.
err分享
err收藏
Provably Secure Fine-Grained Data Access Control Over Multiple Cloud Servers in Mobile Cloud Computing Based Healthcare Applications
err2019-01-01
err123
PREAI
errRoy, Sandip; Das, Ashok Kumar; Chatterjee, Santanu; Kumar, Neeraj; Chattopadhyay, Samiran; Rodrigues, Joel J. P. C.
err分享
err收藏
A Risk Assessment Framework for Cloud Computing
err2016-07-01
err53
errOAAI
errDjemame, Karim; Armstrong, Django; Guitart, Jordi; Macias, Mario
err分享
err收藏
A risk assessment model for selecting cloud service providers
err2016-09-13
err40
errOAAI
errCayirci, Erdal; Garaga, Alexandr; de Oliveira, Anderson Santana; Roudier, Yves
err分享
err收藏
Functional and quality attributes of beef burgers fortified by brown linseed powder
err2022-01-10
err0
errOAAI
errSara Basiri; Mohamamd Hashem Yousefi; Seyed Shahram Shekarforoush
err分享
err收藏
An Efficient and Practical Smart Card Based Anonymity Preserving User Authentication Scheme for TMIS using Elliptic Curve Cryptography
err2015-10-03
err71
PREAI
errAmin, Ruhul; Islam, S. K. Hafizul; Biswas, G. P.; Khan, Muhammad Khurram; Kumar, Neeraj
err分享
err收藏
学者 查看更多内容