DocumentCode :
3532814
Title :
Risk propagation of security SLAs in the cloud
Author :
Hale, Matthew L. ; Gamble, Rose
Author_Institution :
Tandy Sch. of Comput. Sci., Univ. of Tulsa, Tulsa, OK, USA
fYear :
2012
fDate :
3-7 Dec. 2012
Firstpage :
730
Lastpage :
735
Abstract :
For organizations with mission critical systems, moving data or functionality to the cloud introduces a risk of additional exposed vulnerabilities associated with cloud service providers not implementing organizationally selected security controls. When internal system details are abstracted away as part of the cloud architecture, the organization must rely on contractual obligations embedded in service level agreements (SLAs) to assess service offerings for security risk. Whenever an SLA is formed, the level of risk incurred is based on how well the offered service terms meet the organizational security demands. In the cloud, additional SLAs between third party cloud service providers are formed to federate cloud resources, effectively distributing organizational risk among the various providers involved in the negotiated federations or service compositions. At runtime, whenever a cloud or service violates its SLA with respect to security controls or cancels any security offerings, the risk of noncompliance with organizational security policies increases. This paper provides a process to adapt to the propagated changes of service provider security risks within a service composition or federation due to SLA violations. The process is based on a distributed risk-aware renegotiation algorithm that replaces services if they violate SLAs.
Keywords :
Web services; cloud computing; contracts; distributed algorithms; organisational aspects; security of data; SLA violations; cloud resources; cloud service providers; contractual obligations; distributed risk-aware renegotiation algorithm; mission critical systems; moving data; moving functionality; negotiated federations; organizational risk distribution; organizational security demands; organizational security policies; risk propagation; security SLA; security controls; service composition; service level agreements; service offerings; service provider security risks; Algorithm design and analysis; Certification; Cloud computing; Clouds; Organizations; Quality of service; Security; algorithms; audit; certification; cloud computing; matchmaking; quality of security service; risk; security; service level agreement; web services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Globecom Workshops (GC Wkshps), 2012 IEEE
Conference_Location :
Anaheim, CA
Print_ISBN :
978-1-4673-4942-0
Electronic_ISBN :
978-1-4673-4940-6
Type :
conf
DOI :
10.1109/GLOCOMW.2012.6477665
Filename :
6477665
Link To Document :
بازگشت