• DocumentCode
    118515
  • Title

    Measuring security for cloud service provider: A Third Party approach

  • Author

    Whaiduzzaman, Md ; Gani, Abdullah

  • Author_Institution
    Mobile Cloud Comput. Res. Lab., Univ. of Malaya, Kuala Lumpur, Malaysia
  • fYear
    2014
  • fDate
    13-15 Feb. 2014
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Cloud Computing (CC) is a new paradigm of utility computing and enormously growing phenomenon in the present IT industry hype. CC leverages low cost investment opportunity for the new business entrepreneur as well as business avenues for cloud service providers. As the number of the new Cloud Service Customer (CSC) increases, users require a secure, reliable and trustworthy Cloud Service Provider (CSP) from the market to store confidential data. However, a number of shortcomings in reliable monitoring and identifying security risks, threats are an immense concern in choosing the highly secure CSP for the wider cloud community. The secure CSP ranking system is currently a challenging aspect to gauge trust, privacy and security. In this paper, a Trusted Third Party (TTP) like credit rating agency is introduced for security ranking by identifying current assessable security risks. We propose an automated software scripting model by penetration testing for TTP to run on CSP side and identify the vulnerability and check security strength and fault tolerance capacity of the CSP. Using the results, several non-measurable metrics are added and provide the ranking system of secured trustworthy CSP ranking systems. Moreover, we propose a conceptual model for monitoring and maintaining such TTP cloud ranking providers worldwide called federated third party approach. Hence the model of federated third party cloud ranking and monitoring system assures and boosts up the confidence to make a feasible secure and trustworthy market of CSPs.
  • Keywords
    cloud computing; program testing; trusted computing; CC; CSC; CSP fault tolerance capacity; CSP ranking system; CSP security strength; IT industry; TTP; automated software scripting model; business avenues; business entrepreneur; cloud computing; cloud service customer; cloud service provider; confidential data storage; credit rating agency; federated third party approach; information technology; penetration testing; security measurement; security risks identification; security risks monitoring; trusted third party; utility computing; Business; Cloud computing; Measurement; Mobile communication; Monitoring; Security; Cloud computing; cloud security ranking; cloud service provider; trusted third party;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Electrical Information and Communication Technology (EICT), 2013 International Conference on
  • Conference_Location
    Khulna
  • Print_ISBN
    978-1-4799-2297-0
  • Type

    conf

  • DOI
    10.1109/EICT.2014.6777855
  • Filename
    6777855