The Experts below are selected from a list of 45540 Experts worldwide ranked by ideXlab platform

Kim-kwang Raymond Choo - One of the best experts on this subject based on the ideXlab platform.

  • On Cloud Security attacks
    Journal of Network and Computer Applications, 2016
    Co-Authors: Salman Iqbal, Laiha Mat Kiah, Babak Dhaghighi, Muzammil Hussain, Suleman Khan, Muhammad Khurram Khan, Kim-kwang Raymond Choo
    Abstract:

    Major provisioning of Cloud computing is mainly delivered via Software as a Service, Platform as a Service and Infrastructure as a Service. However, these service delivery models are vulnerable to a range of Security attacks, exploiting both Cloud specific and existing web service vulnerabilities. Taxonomies are a useful tool for system designers as they provide a systematic way of understanding, identifying and addressing Security risks. In this research work, Cloud based attacks and vulnerabilities are collected and classify with respect to their Cloud models. We also present taxonomy of Cloud Security attacks and potential mitigation strategies with the aim of providing an in-depth understanding of Security requirements in the Cloud environment. We also highlight the importance of intrusion detection and prevention as a service. Display Omitted Cloud Security Attacks Taxonomy.Cloud Intrusion Detection and Prevention as a Service.Intrusion detection in Cloud computing service models.Need for in-depth advanced Cloud protection systems.

  • The Cloud Security Ecosystem - Cloud Security ecosystem
    The Cloud Security Ecosystem, 2015
    Co-Authors: Kim-kwang Raymond Choo
    Abstract:

    This chapter introduces the reader to the initial developments of the Cloud computing industry, consolidated Cloud-related terminologies, and concepts, and explains the main reasons and causes of the Cloud Security and privacy concerns.

  • The Cloud Security Ecosystem - Cloud Security and forensic readiness: The current state of an IaaS provider
    The Cloud Security Ecosystem, 2015
    Co-Authors: Chaz Vidal, Kim-kwang Raymond Choo
    Abstract:

    Security is a key challenge in the deployment and acceptance of Cloud computing services, and existing research efforts include evaluating the effectiveness of various Security solutions such as Security policy implementations and technological solutions. This chapter examines the Security controls of an existing organization’s Infrastructure as a Service (IaaS) service using existing information and Cloud Security standards and forensic readiness best practices. Areas for improvements are also identified in this chapter.

  • A Cloud Security Risk-Management Strategy
    IEEE Cloud Computing, 2014
    Co-Authors: Kim-kwang Raymond Choo
    Abstract:

    Given the threat of Security breaches, to both Cloud service providers and organizational Cloud service users, Cloud Security and privacy are growing public policy concerns as well a salient area of inquiry for researchers. To ensure organizational competitiveness, Cloud service providers and organizational Cloud service users must make detailed preparations to act against cyberthreats before they occur, and to recover from malicious cyberactivities when such threats succeed. A Cloud Security risk-management strategy should be a dynamic document that's regularly reviewed by stakeholders, and should include policies and objectives that align with the organization's needs.

Dana Petcu - One of the best experts on this subject based on the ideXlab platform.

  • COMPSAC - A Taxonomy for SLA-Based Monitoring of Cloud Security
    2014 IEEE 38th Annual Computer Software and Applications Conference, 2014
    Co-Authors: Dana Petcu
    Abstract:

    A fast analysis of the state-of-the-art can show that SLA-based Cloud Security monitoring services are not yet available. SLA-based Cloud monitoring services are oriented towards performance monitoring, while the current Cloud Security monitoring is not SLA-based. In order to design and implement such a service a first step is the identification of the basic requirements. The taxonomies available for the fields of Cloud computing, monitoring, Security and SLAs are expected to be used. This short note proposes a visual taxonomy intended to serve the design of an SLA-based Cloud Security monitoring.

Kenneth Van Surksum - One of the best experts on this subject based on the ideXlab platform.

Martin Gilje Jaatun - One of the best experts on this subject based on the ideXlab platform.

  • Could the outsourcing of incident response management provide a blueprint for managing other Cloud Security requirements?
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2017
    Co-Authors: Bob Duncan, Mark Whittington, Martin Gilje Jaatun, Alfredo Ramiro Reyes Z????iga
    Abstract:

    In this chapter, we consider whether the outsourcing of incident management is a viable technological approach that may be transferable to other Cloud Security management requirements. We review a viable approach to outsourcing incident response management and consider whether this can be applied to other Cloud Security approaches, starting with the concept of using proper measurement for a Cloud Security assurance model. We demonstrate how this approach can be applied, not only to the approach under review, but how it may be applied to address other Cloud Security requirements.

  • ARES - Towards an Ontology for Cloud Security Obligations
    2013 International Conference on Availability Reliability and Security, 2013
    Co-Authors: Karin Bernsmed, Astrid Undheim, Per Håkon Meland, Martin Gilje Jaatun
    Abstract:

    This paper presents an ontology for Cloud Security obligations, which is based on a number of industry accepted standards and guidelines. The ontology terms and relationships have been defined in the W3C ontology language OWL and includes a number of technical Security controls that can be implemented by public Cloud providers. This paper outlines the ontology and demonstrates how it can be used in two different application areas.

Kakali Chatterjee - One of the best experts on this subject based on the ideXlab platform.

  • Cloud Security issues and challenges
    Journal of Network and Computer Applications, 2017
    Co-Authors: Ashish Singh, Kakali Chatterjee
    Abstract:

    The Cloud computing provides on demand services over the Internet with the help of a large amount of virtual storage. The main features of Cloud computing is that the user does not have any setup of expensive computing infrastructure and the cost of its services is less. In the recent years, Cloud computing integrates with the industry and many other areas, which has been encouraging the researcher to research on new related technologies. Due to the availability of its services & scalability for computing processes individual users and organizations transfer their application, data and services to the Cloud storage server. Regardless of its advantages, the transformation of local computing to remote computing has brought many Security issues and challenges for both consumer and provider. Many Cloud services are provided by the trusted third party which arises new Security threats. The Cloud provider provides its services through the Internet and uses many web technologies that arise new Security issues. This paper discussed about the basic features of the Cloud computing, Security issues, threats and their solutions. Additionally, the paper describes several key topics related to the Cloud, namely Cloud architecture framework, service and deployment model, Cloud technologies, Cloud Security concepts, threats, and attacks. The paper also discusses a lot of open research issues related to the Cloud Security.