Towards Establishing Security-Aware Cloud Markets

被引:1
作者
Wenge, Olga [1 ]
Schuller, Dieter [1 ]
Steinmetz, Ralf [1 ]
机构
[1] Tech Univ Darmstadt, Multimedia Commun Lab KOM, Darmstadt, Germany
来源
2014 IEEE 6TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM) | 2014年
关键词
cloud computing security; cloud collaborations; cloud brokerage; information security governance; risk assessment; cloud certification; security labeling;
D O I
10.1109/CloudCom.2014.159
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Today's cloud environments are very heterogeneous. This cloud heterogeneity, as the consequence of lacking cloud standards, builds technical and security barriers between cloud providers and blocks them from intended cloud collaborations within cloud marketplaces. A cloud broker, who acts on behalf of cloud providers, matches compatible collaborative partners according to their requirements and attempts to support the optimal exchange of cloud resources between them. The fulfillment of security requirements in cloud collaborations usually involves providing risk assessments, which are still very time-consuming and not applicable for ad hoc cloud collaborations within cloud marketplaces. Aiming to design and develop a security model for trading with cloud services, we identify in this paper concepts, mechanism and available tools that can support establishing of security-aware cloud markets. Furthermore, we introduce our information security governance driven cloud brokerage model with security labeling of tradable cloud products that can be the next step in the standardization process of tradable cloud products and optimize the selection of collaborative cloud partners.
引用
收藏
页码:1027 / 1032
页数:6
相关论文
共 28 条
  • [1] Almorsy M., 2011, Proceedings of the 2011 IEEE 4th International Conference on Cloud Computing (CLOUD 2011), P364, DOI 10.1109/CLOUD.2011.9
  • [2] [Anonymous], 2010, P 2 INT WORKSH CLOUD, DOI DOI 10.1145/1871929.1871936
  • [3] [Anonymous], 2006, ISACA INFORM SECURIT
  • [4] Ates M., 2011, 2011 Sixth International Conference on Availability, Reliability and Security, P555, DOI 10.1109/ARES.2011.85
  • [5] Bernsmed K., 2011, 2011 Sixth International Conference on Availability, Reliability and Security, P202, DOI 10.1109/ARES.2011.34
  • [6] Bernstein D., 2012, IEEE INT C CLOUD COM, P537
  • [7] COBIT, KNOWL CTR COBIT PAG
  • [8] Corporation Essvale Corporation Limited, 2008, BUS KNOWL IT PRIM BR
  • [9] Garg S.K., 2011, SPRINGER SCI BUSINES
  • [10] A framework for ranking of cloud computing services
    Garg, Saurabh Kumar
    Versteeg, Steve
    Buyya, Rajkumar
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2013, 29 (04): : 1012 - 1023