• DocumentCode
    1821317
  • Title

    On-Demand Dynamic Security for Risk-Based Secure Collaboration in Clouds

  • Author

    Bertram, S. ; Boniface, M. ; Surridge, M. ; Briscombe, N. ; Hall-May, M.

  • Author_Institution
    IT Innovation Centre, Univ. of Southampton, Southampton, UK
  • fYear
    2010
  • fDate
    5-10 July 2010
  • Firstpage
    518
  • Lastpage
    525
  • Abstract
    Industrial adoption of cloud computing for collaborative business processes is limited by their ability to meet inter-enterprise security requirements. Although some clouds offerings comply with security standards, no solution today allows businesses to assess security compliance of applications at the business level and dynamically link to security countermeasures on-demand. In this paper, we present a Platform-as-a-Service infrastructure that combines semantic security risk management tools with dynamic web service policy frameworks to support the mitigation of security threats throughout the lifecycle of a service-oriented application deployed within the cloud. The platform address the need to model security requirements, dynamically provision and configure security services and link operational security events to vulnerabilities and impact assessments at the business level. The Platform has been evaluated using a collaborative engineering design scenario and a proof-of-concept deployed at a multi-tenant cloud as part of the UK CFMS project. The work is being further enhanced in the European Funded SERSCIS project.
  • Keywords
    Web services; business data processing; security of data; European funded SERSCIS project; UK CFMS project; cloud computing; collaborative business processes; collaborative engineering design scenario; dynamic Web service policy frameworks; inter-enterprise security requirements; multitenant cloud; on-demand dynamic security; platform-as-a-service infrastructure; risk-based secure collaboration; semantic security risk management tools; Access control; Atmospheric modeling; Business; Clouds; Collaboration; Semantics; clouds; risk management; security; service-oriented architecture; trust;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cloud Computing (CLOUD), 2010 IEEE 3rd International Conference on
  • Conference_Location
    Miami, FL
  • Print_ISBN
    978-1-4244-8207-8
  • Electronic_ISBN
    978-0-7695-4130-3
  • Type

    conf

  • DOI
    10.1109/CLOUD.2010.83
  • Filename
    5558017