DocumentCode :
1799757
Title :
AHP-Based Quantitative Approach for Assessing and Comparing Cloud Security
Author :
Taha, Ahmed ; Trapero, Ruben ; Luna, Jesus ; Suri, Neeraj
Author_Institution :
Tech. Univ. Darmstadt, Darmstadt, Germany
fYear :
2014
fDate :
24-26 Sept. 2014
Firstpage :
284
Lastpage :
291
Abstract :
While Cloud usage increasingly involves security considerations, there is still a conspicuous lack of techniques for users to assess/ensure that the security level advertised by the Cloud Service Provider (CSP) is actually delivered. Recent efforts have proposed extending existing Cloud Service Level Agreements (SLAs) to the security domain, by creating Security SLAs (SecLAs) along with attempts to quantify and reason about the security assurance provided by CSPs. However, both technical and usability issues limit their adoption in practice. In this paper we introduce a new technique for conducting quantitative and qualitative analysis of the security level provided by CSPs. Our methodology significantly improves upon contemporary security assessment approaches by creating a novel decision making technique based on the Analytic Hierarchy Process (AHP) that allows the comparison and benchmarking of the security provided by a CSP based on its SecLA. Furthermore, our technique improves security requirements specifications by introducing a flexible and simple methodology that allows users to identify their specific security needs. The proposed technique is demonstrated with real-world CSP data obtained from the Cloud Security Alliance´s Security, Trust and Assurance Registry.
Keywords :
analytic hierarchy process; cloud computing; contracts; security of data; trusted computing; AHP-based quantitative approach; CSP; SecLA; analytic hierarchy process; cloud security; cloud security alliance; cloud service level agreements; cloud service provider; cloud usage; security SLA; security trust and assurance registry; Analytic hierarchy process; Benchmark testing; Europe; Measurement; Privacy; Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Trust, Security and Privacy in Computing and Communications (TrustCom), 2014 IEEE 13th International Conference on
Conference_Location :
Beijing
Type :
conf
DOI :
10.1109/TrustCom.2014.39
Filename :
7011262
Link To Document :
بازگشت