Title :
Semantic search for cloud providers with security conformance to cloud controls matrix
Author :
Thaweejinda, Jakarin ; Senivongse, T.
Author_Institution :
Dept. of Comput. Eng., Chulalongkorn Univ., Bangkok, Thailand
Abstract :
Prospective cloud consumers consider several quality attributes of cloud providers when selecting a cloud service. Security is a major quality attribute that is often used to differentiate between service offers from different cloud providers. Cloud Security Alliance has published the Cloud Controls Matrix (CCM) which contains security best practices and principles which cloud providers should follow to provide secure cloud services. This paper presents a semantic search framework for discovering cloud services which conform to the security controls in the CCM. In this framework, a security ontology is constructed from the CCM, and based on this security ontology, provider profiles can be built. A provider profile which presents relevant evidence of conformance to CCM security controls is then searched and ranked against a cloud consumer´s query. Cloud consumers then can determine and compare the degree of conformance of the cloud services to the CCM. In an experiment, the semantic search gives the search results that should be more useful to the consumers than normal text search.
Keywords :
cloud computing; ontologies (artificial intelligence); security of data; CCM security controls; cloud consumer query; cloud consumers; cloud controls matrix; cloud providers; cloud security alliance; cloud services; security conformance; security ontology; semantic search framework; text search; cloud computing; ontology; security; service discovery;
Conference_Titel :
Computer Science and Software Engineering (JCSSE), 2014 11th International Joint Conference on
Conference_Location :
Chon Buri
Print_ISBN :
978-1-4799-5821-4
DOI :
10.1109/JCSSE.2014.6841882