From Security to Assurance in the Cloud: A Survey

被引:99
作者
Ardagna, Claudio A. [1 ]
Asal, Rasool [2 ]
Damiani, Ernesto [1 ,2 ]
Quang Hieu Vu [2 ]
机构
[1] Univ Milan, Dipartimento Informat, I-26013 Crema, CR, Italy
[2] Khalifa Univ, ETISALAT BT Innovat Ctr, Abu Dhabi 127788, U Arab Emirates
关键词
Security; Verification Assurance; cloud computing; security; survey; transparency; INTRUSION DETECTION; COMPUTING SECURITY; SERVICE SELECTION; ACCESS-CONTROL; PRIVACY; AUTHENTICATION; FRAMEWORK; CHALLENGES; IMPLEMENTATION; ENVIRONMENTS;
D O I
10.1145/2767005
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The cloud computing paradigm has become a mainstream solution for the deployment of business processes and applications. In the public cloud vision, infrastructure, platform, and software services are provisioned to tenants (i.e., customers and service providers) on a pay-as-you-go basis. Cloud tenants can use cloud resources at lower prices, and higher performance and flexibility, than traditional on-premises resources, without having to care about infrastructure management. Still, cloud tenants remain concerned with the cloud's level of service and the nonfunctional properties their applications can count on. In the last few years, the research community has been focusing on the nonfunctional aspects of the cloud paradigm, among which cloud security stands out. Several approaches to security have been described and summarized in general surveys on cloud security techniques. The survey in this article focuses on the interface between cloud security and cloud security assurance. First, we provide an overview of the state of the art on cloud security. Then, we introduce the notion of cloud security assurance and analyze its growing impact on cloud security approaches. Finally, we present some recommendations for the development of next-generation cloud security and assurance solutions.
引用
收藏
页数:50
相关论文
共 293 条
[1]   Cloud monitoring: A survey [J].
Aceto, Giuseppe ;
Botta, Alessio ;
de Donato, Walter ;
Pescape, Antonio .
COMPUTER NETWORKS, 2013, 57 (09) :2093-2115
[2]  
Advanced Security Service cERTificate for SOA, 2010, ADV SECURITY SERVICE
[3]   GridICE: a monitoring service for Grid systems [J].
Andreozzi, S ;
De Bortoli, N ;
Fantinel, S ;
Ghiselli, A ;
Rubini, GL ;
Tortone, G ;
Vistoli, MC .
FUTURE GENERATION COMPUTER SYSTEMS, 2005, 21 (04) :559-571
[4]   A Test-Based Security Certification Scheme for Web Services [J].
Anisetti, Marco ;
Ardagna, Claudio A. ;
Damiani, Ernesto ;
Saonara, Francesco .
ACM TRANSACTIONS ON THE WEB, 2013, 7 (02)
[5]  
[Anonymous], P ACM CCSW 2010
[6]  
[Anonymous], IJIM
[7]  
[Anonymous], SEC PRIV ASS DAT SER
[8]  
[Anonymous], P ACM CCS 2011
[9]  
[Anonymous], P ACSAC 2012
[10]  
[Anonymous], P IEEE CLOUD 2012