基于风险和依赖性的云服务安全评估标准规范

Sarah Maroc, J. Zhang
{"title":"基于风险和依赖性的云服务安全评估标准规范","authors":"Sarah Maroc, J. Zhang","doi":"10.1109/ICCSN.2019.8905370","DOIUrl":null,"url":null,"abstract":"A key problem with much of the literature on cloud services evaluation is that it fails to consider the context and the dependencies between the evaluation criteria spanning different services and the various, and often conflicting, customers' requirements. Different aspects are important for different applications, and the choice of evaluation criteria needs to reflect this. This paper proposes a method for selecting the core security evaluation criteria based on the cause-effect relationships between the services, threats, vulnerabilities, and security controls using multiple evaluation factors including the importance, likelihood, and impact. The Analytic Network Process (ANP) is used to estimate the direct influence between the attributes, and the Decision Making Trial and Evaluation Laboratory (DEMATEL) is used to obtain the total influences (direct and indirect) between those attributes. The goal is not to blindly use all the criteria that exist in the literature, but instead to identify those that are most relevant to the context of the evaluation considering the characteristics of cloud service models, deployment models, and the overall evaluation context. This allows to focus on the situation and eliminate unnecessary tasks.","PeriodicalId":330766,"journal":{"name":"2019 IEEE 11th International Conference on Communication Software and Networks (ICCSN)","volume":"29 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Risk-Based and Dependency-Aware Criteria Specification for Cloud Services Security Evaluation\",\"authors\":\"Sarah Maroc, J. Zhang\",\"doi\":\"10.1109/ICCSN.2019.8905370\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"A key problem with much of the literature on cloud services evaluation is that it fails to consider the context and the dependencies between the evaluation criteria spanning different services and the various, and often conflicting, customers' requirements. Different aspects are important for different applications, and the choice of evaluation criteria needs to reflect this. This paper proposes a method for selecting the core security evaluation criteria based on the cause-effect relationships between the services, threats, vulnerabilities, and security controls using multiple evaluation factors including the importance, likelihood, and impact. The Analytic Network Process (ANP) is used to estimate the direct influence between the attributes, and the Decision Making Trial and Evaluation Laboratory (DEMATEL) is used to obtain the total influences (direct and indirect) between those attributes. The goal is not to blindly use all the criteria that exist in the literature, but instead to identify those that are most relevant to the context of the evaluation considering the characteristics of cloud service models, deployment models, and the overall evaluation context. This allows to focus on the situation and eliminate unnecessary tasks.\",\"PeriodicalId\":330766,\"journal\":{\"name\":\"2019 IEEE 11th International Conference on Communication Software and Networks (ICCSN)\",\"volume\":\"29 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-06-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2019 IEEE 11th International Conference on Communication Software and Networks (ICCSN)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICCSN.2019.8905370\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 IEEE 11th International Conference on Communication Software and Networks (ICCSN)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCSN.2019.8905370","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

关于云服务评估的许多文献的一个关键问题是,它们没有考虑上下文和跨越不同服务的评估标准之间的依赖关系,以及各种(通常是相互冲突的)客户需求。不同的方面对不同的应用很重要,评价标准的选择需要反映这一点。本文提出了一种基于服务、威胁、漏洞、安全控制之间的因果关系,采用重要性、可能性、影响等多重评价因素选择核心安全评价标准的方法。分析网络过程(ANP)用于估计属性之间的直接影响,决策试验和评估实验室(DEMATEL)用于获得这些属性之间的总影响(直接和间接)。我们的目标不是盲目地使用文献中存在的所有标准,而是根据云服务模型、部署模型和整体评估上下文的特征,确定那些与评估上下文最相关的标准。这可以让你专注于情况,消除不必要的任务。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Risk-Based and Dependency-Aware Criteria Specification for Cloud Services Security Evaluation
A key problem with much of the literature on cloud services evaluation is that it fails to consider the context and the dependencies between the evaluation criteria spanning different services and the various, and often conflicting, customers' requirements. Different aspects are important for different applications, and the choice of evaluation criteria needs to reflect this. This paper proposes a method for selecting the core security evaluation criteria based on the cause-effect relationships between the services, threats, vulnerabilities, and security controls using multiple evaluation factors including the importance, likelihood, and impact. The Analytic Network Process (ANP) is used to estimate the direct influence between the attributes, and the Decision Making Trial and Evaluation Laboratory (DEMATEL) is used to obtain the total influences (direct and indirect) between those attributes. The goal is not to blindly use all the criteria that exist in the literature, but instead to identify those that are most relevant to the context of the evaluation considering the characteristics of cloud service models, deployment models, and the overall evaluation context. This allows to focus on the situation and eliminate unnecessary tasks.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信