Home > Research > Publications & Outputs > A multi-layer and multi-tenant cloud assurance ...
View graph of relations

A multi-layer and multi-tenant cloud assurance evaluation methodology

Research output: Contribution in Book/Report/Proceedings - With ISBN/ISSNConference contribution/Paperpeer-review

Published
  • Aleksandre Hudic
  • Markus Tauber
  • Thomas Lorunser
  • Maria Krotsiani
  • George Spanoudakis
  • Andreas Mauthe
  • E. R. Weippl
Close
Publication date12/2014
Host publicationProceedings of 6th IEEE International Conference on Cloud Computing Technology and Science, IEEE Cloud Comp 2014,
Place of PublicationPiscataway, N.J.
PublisherIEEE
Pages386-393
Number of pages8
ISBN (print)9781479940936
<mark>Original language</mark>English

Abstract

Data with high security requirements is being processed and stored with increasing frequency in the Cloud. To guarantee that the data is being dealt in a secure manner we investigate the applicability of Assurance methodologies. In a typical Cloud environment the setup of multiple layers and different stakeholders determines security properties of individual components that are used to compose Cloud applications. We present a methodology adapted from Common Criteria for aggregating information reflecting the security properties of individual constituent components of Cloud applications. This aggregated information is used to categorise overall application security in terms of Assurance Levels and to provide a continuous assurance level evaluation. It gives the service owner an overview of the security of his service, without requiring detailed manual analyses of log files.