DocumentCode :
1821317
Title :
On-Demand Dynamic Security for Risk-Based Secure Collaboration in Clouds
Author :
Bertram, S. ; Boniface, M. ; Surridge, M. ; Briscombe, N. ; Hall-May, M.
Author_Institution :
IT Innovation Centre, Univ. of Southampton, Southampton, UK
fYear :
2010
fDate :
5-10 July 2010
Firstpage :
518
Lastpage :
525
Abstract :
Industrial adoption of cloud computing for collaborative business processes is limited by their ability to meet inter-enterprise security requirements. Although some clouds offerings comply with security standards, no solution today allows businesses to assess security compliance of applications at the business level and dynamically link to security countermeasures on-demand. In this paper, we present a Platform-as-a-Service infrastructure that combines semantic security risk management tools with dynamic web service policy frameworks to support the mitigation of security threats throughout the lifecycle of a service-oriented application deployed within the cloud. The platform address the need to model security requirements, dynamically provision and configure security services and link operational security events to vulnerabilities and impact assessments at the business level. The Platform has been evaluated using a collaborative engineering design scenario and a proof-of-concept deployed at a multi-tenant cloud as part of the UK CFMS project. The work is being further enhanced in the European Funded SERSCIS project.
Keywords :
Web services; business data processing; security of data; European funded SERSCIS project; UK CFMS project; cloud computing; collaborative business processes; collaborative engineering design scenario; dynamic Web service policy frameworks; inter-enterprise security requirements; multitenant cloud; on-demand dynamic security; platform-as-a-service infrastructure; risk-based secure collaboration; semantic security risk management tools; Access control; Atmospheric modeling; Business; Clouds; Collaboration; Semantics; clouds; risk management; security; service-oriented architecture; trust;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Cloud Computing (CLOUD), 2010 IEEE 3rd International Conference on
Conference_Location :
Miami, FL
Print_ISBN :
978-1-4244-8207-8
Electronic_ISBN :
978-0-7695-4130-3
Type :
conf
DOI :
10.1109/CLOUD.2010.83
Filename :
5558017
Link To Document :
بازگشت