Ontology-based Negotiation of security requirements in cloud

L. Liccardo, M. Rak, G. Modica, O. Tomarchio
{"title":"Ontology-based Negotiation of security requirements in cloud","authors":"L. Liccardo, M. Rak, G. Modica, O. Tomarchio","doi":"10.1109/CASoN.2012.6412401","DOIUrl":null,"url":null,"abstract":"The Cloud Computing paradigm attracts many customers because of the potentialities it promises. Despite of many benefits, a widespread adoption is limited by many issues that potential customers still have to face. Security in the cloud is one of the main concern for the customer. The Cloud Service Provider (CSP) is responsible of providing security to customers and assuring that their data and application are properly secured. In this context, the concept of Service Level Agreement (SLA) assumes a great importance. It can be used as a means to formalize and establish in a contract what must effectively be granted in terms of security levels. There is actually Semantic Gap between how security guarantees are intended respectively by customers and providers. A customer is inclined to express security in terms of high-level requirements, while a CSP expresses guarantees through a technical, low-level language. To address this gap, the key is to find a common language for both the customer and the CSP. The goal of this paper is to offer an Ontology-based Negotiation Service allowing a customer to negotiate the interested security level among different CSPs, with the possibility to choose the best security offering; a Security Ontology was developed as a basis for a common semantic language that customers and providers will have to use to express security features and requirements.","PeriodicalId":431370,"journal":{"name":"2012 Fourth International Conference on Computational Aspects of Social Networks (CASoN)","volume":"168 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2012-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2012 Fourth International Conference on Computational Aspects of Social Networks (CASoN)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CASoN.2012.6412401","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 10

Abstract

The Cloud Computing paradigm attracts many customers because of the potentialities it promises. Despite of many benefits, a widespread adoption is limited by many issues that potential customers still have to face. Security in the cloud is one of the main concern for the customer. The Cloud Service Provider (CSP) is responsible of providing security to customers and assuring that their data and application are properly secured. In this context, the concept of Service Level Agreement (SLA) assumes a great importance. It can be used as a means to formalize and establish in a contract what must effectively be granted in terms of security levels. There is actually Semantic Gap between how security guarantees are intended respectively by customers and providers. A customer is inclined to express security in terms of high-level requirements, while a CSP expresses guarantees through a technical, low-level language. To address this gap, the key is to find a common language for both the customer and the CSP. The goal of this paper is to offer an Ontology-based Negotiation Service allowing a customer to negotiate the interested security level among different CSPs, with the possibility to choose the best security offering; a Security Ontology was developed as a basis for a common semantic language that customers and providers will have to use to express security features and requirements.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
云环境中基于本体的安全需求协商
云计算范式吸引了许多客户,因为它所承诺的潜力。尽管有很多好处,但广泛采用仍然受到潜在客户必须面对的许多问题的限制。云中的安全性是客户主要关心的问题之一。云服务提供商(CSP)负责为客户提供安全性,并确保他们的数据和应用程序得到适当的保护。在这种情况下,服务水平协议(SLA)的概念非常重要。它可以作为一种手段,在合同中形式化和建立必须在安全级别方面有效授予的内容。实际上,客户和提供商对安全保证的预期存在语义上的差距。客户倾向于用高级需求来表达安全性,而CSP则通过技术性的低级语言来表达保证。要解决这一差距,关键是为客户和CSP找到一种通用语言。本文的目标是提供一种基于本体的协商服务,允许客户在不同的csp之间协商感兴趣的安全级别,并有可能选择最佳的安全产品;安全本体是作为公共语义语言的基础而开发的,客户和提供者将不得不使用这种语言来表达安全特性和需求。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Boosting Optimum-Path Forest clustering through harmony Search and its applications for intrusion detection in computer networks Graph-based cross-validated committees ensembles Automatic sentiment analysis of Twitter messages Identifying focal patterns in social networks Ontology-based Negotiation of security requirements in cloud
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1