The Experts below are selected from a list of 2331 Experts worldwide ranked by ideXlab platform
Moussa Ouedraogo - One of the best experts on this subject based on the ideXlab platform.
-
Security transparency: the next frontier for security research in the Cloud
Journal of Cloud Computing, 2015Co-Authors: Moussa Ouedraogo, Severine Mignon, Herve Cholez, Steven Furnell, Eric DuboisAbstract:The recent advances in networking and the ubiquity of the Internet have enabled the emergence of Cloud computing as a viable solution for a convenient, elastic and economical usage of Services. In spite of these apparent advantages, the Cloud model presents some challenges that hamper its wider adoption, most of which relate to security and privacy. This paper provides a review of the current initiatives devised by both academia and industry for addressing the security concerns inherent to the Cloud model. Our analysis of the state of the art reveals that although initiatives such as SLA and virtual machines monitoring, and recent development in encryption mechanisms, have contributed to addressing some of the salient issues of security and privacy in the Cloud, larger initiatives, other than standards, aiming at enabling security transparency and a mutual auditability in the Cloud remain to be seen. With this in mind, the paper proposes some routes towards related solutions by discussing a number of desiderata for establishing a better security transparency between a Cloud Service Provider (CSP) and a Cloud Service Consumer (CSC). Given the current reluctance of some major businesses to embrace the trend, owing mainly to the devolution of some of the security aspects to a third party, the authors argue that undertaking some initiatives in that direction is a key to sustaining the current momentum of the Cloud.
-
selecting a Cloud Service provider in the age of cybercrime
Computers & Security, 2013Co-Authors: Moussa Ouedraogo, Haralambos MouratidisAbstract:The benefits of resorting to the Cloud, as an efficient way to provide Services, have long been recognised in the academic and industrial literature. However, as more and more companies are beginning to embrace the trend, it has also become clearer that the model offers unprecedented opportunities to cybercriminals: either by enabling them to compromise a myriad of Services in a single shot or by allowing cyber-criminals to amplify their capabilities through a leverage of the technology offered by the Cloud. This paper highlights the importance of an informed choice of a Cloud Service Provider (CSP) in minimising one's exposure to the insecurity of a Cloud context. The paper proposes a well-defined approach, known as the Complete-Auditable-Reportable or C.A.RE, as a way to minimise one's exposure to the insecurity we live within the Cloud. The C.A.RE approach helps to determine the adequacy of a CSP sponsored security by assessing its completeness in addressing most, if not all, risks that a Service may be exposed to; the potential of that security to be adapted upon the identification of a security vulnerability during an audit, and how transparently such information is shared with the concerned Cloud Service Consumer (CSC). A level of assurance is associated to each of the C.A.RE parameters in order to help determine the overall trustworthiness of a CSP. The analysis and comparison of the C.A.RE approach to a well-known guideline as the Cloud Service Security Alliance guidelines, reveals that C.A.RE offers a clear and efficient way in determining a Trusted Cloud Service.
Haralambos Mouratidis - One of the best experts on this subject based on the ideXlab platform.
-
selecting a Cloud Service provider in the age of cybercrime
Computers & Security, 2013Co-Authors: Moussa Ouedraogo, Haralambos MouratidisAbstract:The benefits of resorting to the Cloud, as an efficient way to provide Services, have long been recognised in the academic and industrial literature. However, as more and more companies are beginning to embrace the trend, it has also become clearer that the model offers unprecedented opportunities to cybercriminals: either by enabling them to compromise a myriad of Services in a single shot or by allowing cyber-criminals to amplify their capabilities through a leverage of the technology offered by the Cloud. This paper highlights the importance of an informed choice of a Cloud Service Provider (CSP) in minimising one's exposure to the insecurity of a Cloud context. The paper proposes a well-defined approach, known as the Complete-Auditable-Reportable or C.A.RE, as a way to minimise one's exposure to the insecurity we live within the Cloud. The C.A.RE approach helps to determine the adequacy of a CSP sponsored security by assessing its completeness in addressing most, if not all, risks that a Service may be exposed to; the potential of that security to be adapted upon the identification of a security vulnerability during an audit, and how transparently such information is shared with the concerned Cloud Service Consumer (CSC). A level of assurance is associated to each of the C.A.RE parameters in order to help determine the overall trustworthiness of a CSP. The analysis and comparison of the C.A.RE approach to a well-known guideline as the Cloud Service Security Alliance guidelines, reveals that C.A.RE offers a clear and efficient way in determining a Trusted Cloud Service.
Surendra Kumar - One of the best experts on this subject based on the ideXlab platform.
-
Conceptual Service Level Agreement Mechanism to Minimize the SLA Violation with SLA Negotiation Process in Cloud Computing Environment
'College of Science for Women', 2021Co-Authors: Narander Kumar, Surendra KumarAbstract:Online Service is used to be as Pay-Per-Use in Cloud computing. Service user need not be in a long time contract with Cloud Service providers. Service level agreements (SLAs) are understandings marked between a Cloud Service providers and others, for example, a Service user, intermediary operator, or observing operators. Since Cloud computing is an ongoing technology giving numerous Services to basic business applications and adaptable systems to manage online agreements are significant. SLA maintains the quality-of-Service to the Cloud user. If Service provider fails to maintain the required Service SLA is considered to be SLA violated. The main aim is to minimize the SLA violations for maintain the QoS of their Cloud users. In this research article, a toolbox is proposed to help the procedure of exchanging of a SLA with the Service providers that will enable the Cloud client in indicating Service quality demands and an algorithm as well as Negotiation model is also proposed to negotiate the request with the Service providers to produce a better agreement between Service provider and Cloud Service Consumer. Subsequently, the discussed framework can reduce SLA violations as well as negotiation disappointments and have expanded cost-adequacy. Moreover, the suggested SLA toolkit is additionally productive to clients so clients can secure a sensible value repayment for diminished QoS or conceding time. This research shows the assurance level in the Cloud Service providers can be kept up by as yet conveying the Services with no interruption from the client's perspectiv
Eric Dubois - One of the best experts on this subject based on the ideXlab platform.
-
Security transparency: the next frontier for security research in the Cloud
Journal of Cloud Computing, 2015Co-Authors: Moussa Ouedraogo, Severine Mignon, Herve Cholez, Steven Furnell, Eric DuboisAbstract:The recent advances in networking and the ubiquity of the Internet have enabled the emergence of Cloud computing as a viable solution for a convenient, elastic and economical usage of Services. In spite of these apparent advantages, the Cloud model presents some challenges that hamper its wider adoption, most of which relate to security and privacy. This paper provides a review of the current initiatives devised by both academia and industry for addressing the security concerns inherent to the Cloud model. Our analysis of the state of the art reveals that although initiatives such as SLA and virtual machines monitoring, and recent development in encryption mechanisms, have contributed to addressing some of the salient issues of security and privacy in the Cloud, larger initiatives, other than standards, aiming at enabling security transparency and a mutual auditability in the Cloud remain to be seen. With this in mind, the paper proposes some routes towards related solutions by discussing a number of desiderata for establishing a better security transparency between a Cloud Service Provider (CSP) and a Cloud Service Consumer (CSC). Given the current reluctance of some major businesses to embrace the trend, owing mainly to the devolution of some of the security aspects to a third party, the authors argue that undertaking some initiatives in that direction is a key to sustaining the current momentum of the Cloud.
Narander Kumar - One of the best experts on this subject based on the ideXlab platform.
-
Conceptual Service Level Agreement Mechanism to Minimize the SLA Violation with SLA Negotiation Process in Cloud Computing Environment
'College of Science for Women', 2021Co-Authors: Narander Kumar, Surendra KumarAbstract:Online Service is used to be as Pay-Per-Use in Cloud computing. Service user need not be in a long time contract with Cloud Service providers. Service level agreements (SLAs) are understandings marked between a Cloud Service providers and others, for example, a Service user, intermediary operator, or observing operators. Since Cloud computing is an ongoing technology giving numerous Services to basic business applications and adaptable systems to manage online agreements are significant. SLA maintains the quality-of-Service to the Cloud user. If Service provider fails to maintain the required Service SLA is considered to be SLA violated. The main aim is to minimize the SLA violations for maintain the QoS of their Cloud users. In this research article, a toolbox is proposed to help the procedure of exchanging of a SLA with the Service providers that will enable the Cloud client in indicating Service quality demands and an algorithm as well as Negotiation model is also proposed to negotiate the request with the Service providers to produce a better agreement between Service provider and Cloud Service Consumer. Subsequently, the discussed framework can reduce SLA violations as well as negotiation disappointments and have expanded cost-adequacy. Moreover, the suggested SLA toolkit is additionally productive to clients so clients can secure a sensible value repayment for diminished QoS or conceding time. This research shows the assurance level in the Cloud Service providers can be kept up by as yet conveying the Services with no interruption from the client's perspectiv