2012 IEEE 14th International Symposium on High-Assurance Systems Engineering 2012
DOI: 10.1109/hase.2012.16
|View full text |Cite
|
Sign up to set email alerts
|

Certifying Services in Cloud: The Case for a Hybrid, Incremental and Multi-layer Approach

Abstract: This is the unspecified version of the paper.This version of the publication may differ from the final published version. Permanent repository link:

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
17
0

Year Published

2013
2013
2020
2020

Publication Types

Select...
4
2
1

Relationship

3
4

Authors

Journals

citations
Cited by 16 publications
(17 citation statements)
references
References 6 publications
0
17
0
Order By: Relevance
“…From a different point of view, Grobauer et al [2011] provide an overview of current vulnerabilities affecting the cloud at different levels, and identify certification as a preferred approach for vulnerability management. Spanoudakis et al [2012] discuss the need of providing novel models for cloud service certification and present a hybrid, incremental, and multilayer approach to cloud certification. Sunyaev and Schneider [2013] present an overview of the possible benefits a certification solution for cloud services could give to all cloud actors, addressing the lack of transparency, trust, and acceptance.…”
Section: Certificationmentioning
confidence: 99%
See 1 more Smart Citation
“…From a different point of view, Grobauer et al [2011] provide an overview of current vulnerabilities affecting the cloud at different levels, and identify certification as a preferred approach for vulnerability management. Spanoudakis et al [2012] discuss the need of providing novel models for cloud service certification and present a hybrid, incremental, and multilayer approach to cloud certification. Sunyaev and Schneider [2013] present an overview of the possible benefits a certification solution for cloud services could give to all cloud actors, addressing the lack of transparency, trust, and acceptance.…”
Section: Certificationmentioning
confidence: 99%
“…The concept of transparency, that is, higher access to low-level (back-end) data produced by the cloud infrastructure and to evidence collected on the security of cloud data and applications, has been recognized as the basis for an effective approach to cloud assurance Spanoudakis et al 2012]. Lack of transparency in fact makes the cloud and its security issues not clear to end users.…”
Section: Cloud Assurancementioning
confidence: 99%
“…Happens(e(_e3,_TOC,_CA, REQ,_notifO(_cred,_data,_auth,_h),_TOC),t3,[t2,t2+d2])) 1 . The above model has two limitations in providing assurance for the integrity-at-rest property: (1) it cannot capture updates of data that might have been carried out without using the update interface assumed of _TOC (i.e., _updOp(_cred,_data,_vCode)), and (2) it cannot check that the operation _updOp has checked authorisation rights before updating data, and A hybrid model could be used in this case to overcome partially the first of these limitations.…”
Section: Example 1: Hybrid Dependent Mode Modelsmentioning
confidence: 99%
“…Our approach is based on the cloud certification framework of the CUMULUS project [1]. In this paper, we introduce the basic concepts of hybrid certification models and present examples of such models formalised using EC-Assertion (i.e., the monitoring language of the CUMULUS framework).…”
Section: Introductionmentioning
confidence: 99%
See 1 more Smart Citation