• DocumentCode
    3704086
  • Title

    A Taxonomy of Cloud Attack Consequences and Mitigation Strategies: The Role of Access Control and Privileged Access Management

  • Author

    Kin Suntana Tep;Ben Martini;Ray Hunt;Kim-Kwang Raymond Choo

  • Author_Institution
    Inf. Assurance Res. Group, Univ. of South Australia, Adelaide, SA, Australia
  • Volume
    1
  • fYear
    2015
  • Firstpage
    1073
  • Lastpage
    1080
  • Abstract
    Cloud services are now used by many organizations for the computation and storage of both public and sensitive data. Organizations expect that the data stored on clouds will be reasonably protected in terms of confidentiality, integrity and availability (CIA). In this paper, we review the cloud security literature to determine key contemporary attack consequences and mitigation strategies in the cloud environment. We categorize the consequences and mitigation strategies using the people, process and technology (PPT) and CIA classifications. We then construct a taxonomy of consequences and mitigation strategies, and use the themes discovered to present a conceptual privileged access management architecture.
  • Keywords
    "Cloud computing","Security","Organizations","Hardware","Taxonomy","Distributed databases"
  • Publisher
    ieee
  • Conference_Titel
    Trustcom/BigDataSE/ISPA, 2015 IEEE
  • Type

    conf

  • DOI
    10.1109/Trustcom.2015.485
  • Filename
    7345393