DocumentCode :
2130048
Title :
Structured Pattern-Based Security Requirements Elicitation for Clouds
Author :
Beckers, Kristian ; Heisel, Maritta ; Cote, Isabelle ; Goeke, Ludger ; Guler, Samet
Author_Institution :
paluno - The Ruhr Inst. for Software Technol., Univ. Duisburg-Essen, Duisburg, Germany
fYear :
2013
fDate :
2-6 Sept. 2013
Firstpage :
465
Lastpage :
474
Abstract :
Economic benefits make cloud computing systems a very attractive alternative to traditional IT-systems. However, numerous concerns about the security of cloud computing services exist. Potential cloud customers have to be confident that the cloud services they acquire are secure for them to use. Therefore, they have to have a clear set of security requirements covering their security needs. Eliciting these requirements is a difficult task, because of the amount of stakeholders and technical components to consider in a cloud environment. That is why we propose a structured, pattern-based method supporting eliciting security requirements. The method guides a potential cloud customer to model a cloud system via our cloud system analysis pattern. The instantiated pattern establishes the context of a cloud scenario. Then, the information of the instantiated pattern can be used to fill-out our textual security requirements patterns. The presented method is tool-supported. Our tool supports the instantiation of the cloud system analysis pattern and automatically transferes the information from the instance to the security requirements patterns. In addition, we have validation conditions that check e.g., if a security requirement refers to at least one element in the cloud. We illustrate our method using an online-banking system as running example.
Keywords :
cloud computing; program verification; security of data; cloud computing systems; cloud services; cloud system analysis pattern; online-banking system; security requirements patterns; structured pattern-based security requirements elicitation; validation conditions; Business; Cloud computing; Security; Servers; Unified modeling language; Virtual machining; ISO 27001; cloud computing; requirements patterns; security requirements engineering; security standards;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Availability, Reliability and Security (ARES), 2013 Eighth International Conference on
Conference_Location :
Regensburg
Type :
conf
DOI :
10.1109/ARES.2013.61
Filename :
6657277
Link To Document :
بازگشت