Optimus: Framework of Vulnerabilities, Attacks, Defenses and SLA Ontologies.
Chen-Yu Lee, Patrick Kamongi, Krishna M. Kavi, Mahadevan Gomathisankaran · INTERNATIONAL JOURNAL OF NEXT-GENERATION COMPUTING · 2015
Maintaining security and privacy in the Cloud is a complex task. The task is made even more challenging as the number of vulnerabilities associated with the cloud infrastructure, and applications are increasing very rapidly. Understanding the security service level agreements (SSLAs) and privacy policies offered by the service and infrastructure providers is critical for consumers to assess the risks of the Cloud before they consider migrating their IT operations to the Cloud. To address these concerns related to the assessment of security and privacy risks of Cloud, we have developed a framework that relies on ontologies that obtain different objects, policies and vulnerabilities. Our framework called Optimus, utilizes three related ontologies: the vulnerability knowledge base (OKB) and ontologies for representing security SLAs (SSLA). Our framework can be used to assess the risks associated with a cloud services and system configurations using our vulnerability ontologies. The risk assessment may be useful to both the provider and consumer of the cloud services. Our ontologies for SSLAs can be used to understand the security agreements of a provider, to negotiate desired security levels, and to audit the compliance of a provider with respect to federal regulations (such as HIPAA). In this paper, we describe our Optimus framework and provide some examples of its application.