Preliminary Design of a Platform-as-a-Service to Provide Security in Cloud
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano · 2014
Cloud computing is an emerging paradigm, recently widely adopted in distributed and business computing. Even if it is very attractive, due to its business model (pay-per-use) and its flexibility (self-service on demand approach), one of the main limits for its adoption is the perception of loss of security and control over resources that are dynamically acquired in the cloud and that reside on remote providers. Moreover, security mechanisms are usually integrated into system architectures, and are not offered to users in a way that enables customization and is easy to use. As a consequence, as far as security is concerned, cloud customers are usually tied to a limited set of offerings made available by providers, often without real grants about the way in which such mechanisms are actually implemented and enforced. This paper deals with the architecture underlying the SPECS platform, which aims at offering security features by an as-a-service approach, using Service Level Agreements as a mean for clear statement between customers and providers to define mutual rights and constraints. The goal is to show the main requirements of such platform and to present the global architecture, in terms of components and their interactions, dedicated to negotiate, to monitor and to enforce the security mechanisms to be applied over existing cloud providers.