DocumentCode
2130048
Title
Structured Pattern-Based Security Requirements Elicitation for Clouds
Author
Beckers, Kristian ; Heisel, Maritta ; Cote, Isabelle ; Goeke, Ludger ; Guler, Samet
Author_Institution
paluno - The Ruhr Inst. for Software Technol., Univ. Duisburg-Essen, Duisburg, Germany
fYear
2013
fDate
2-6 Sept. 2013
Firstpage
465
Lastpage
474
Abstract
Economic benefits make cloud computing systems a very attractive alternative to traditional IT-systems. However, numerous concerns about the security of cloud computing services exist. Potential cloud customers have to be confident that the cloud services they acquire are secure for them to use. Therefore, they have to have a clear set of security requirements covering their security needs. Eliciting these requirements is a difficult task, because of the amount of stakeholders and technical components to consider in a cloud environment. That is why we propose a structured, pattern-based method supporting eliciting security requirements. The method guides a potential cloud customer to model a cloud system via our cloud system analysis pattern. The instantiated pattern establishes the context of a cloud scenario. Then, the information of the instantiated pattern can be used to fill-out our textual security requirements patterns. The presented method is tool-supported. Our tool supports the instantiation of the cloud system analysis pattern and automatically transferes the information from the instance to the security requirements patterns. In addition, we have validation conditions that check e.g., if a security requirement refers to at least one element in the cloud. We illustrate our method using an online-banking system as running example.
Keywords
cloud computing; program verification; security of data; cloud computing systems; cloud services; cloud system analysis pattern; online-banking system; security requirements patterns; structured pattern-based security requirements elicitation; validation conditions; Business; Cloud computing; Security; Servers; Unified modeling language; Virtual machining; ISO 27001; cloud computing; requirements patterns; security requirements engineering; security standards;
fLanguage
English
Publisher
ieee
Conference_Titel
Availability, Reliability and Security (ARES), 2013 Eighth International Conference on
Conference_Location
Regensburg
Type
conf
DOI
10.1109/ARES.2013.61
Filename
6657277
Link To Document