Loughborough University
Leicestershire, UK
LE11 3TU
+44 (0)1509 263171
Loughborough University

Loughborough University Institutional Repository

Please use this identifier to cite or link to this item: https://dspace.lboro.ac.uk/2134/21437

Title: Assessing data breach risk in cloud systems
Authors: Rahulamathavan, Yogachandran
Rajarajan, Muttukrishnan
Rana, Omer F.
Awan, Malik S.
Burnap, Peter
Das, Sajal K.
Keywords: Cloud computing
Issue Date: 2016
Publisher: © IEEE
Citation: RAHULAMATHAVAN, Y. ... et al., 2016. Assessing data breach risk in cloud systems. IN: Proceedings of 2015 7th IEEE International Conference on Cloud Computing Technology and Science (CloudCom 2015), Vancouver, Canada, 30 November-3 December 2015, pp.363-370.
Abstract: The emerging cloud market introduces a multitude of cloud service providers, making it difficult for consumers to select providers who are likely to be a low risk from a security perspective. Recently, significant emphasis has arisen on the need to specify Service Level Agreements that address security concerns of consumers (referred to as SecSLAs) - these are intended to clarify security support in addition to Quality of Service characteristics associated with services. It has been found that such SecSLAs are not consistent among providers, even though they offer services with similar functionality. However, measuring security service levels and the associated risk plays an important role when choosing a cloud provider. Data breaches have been identified as a high priority threat influencing the adoption of cloud computing. This paper proposes a general analysis framework which can compute risk associated with data breaches based on pre-agreed SecSLAs for different cloud providers. The framework exploits a tree based structure to identify possible attack scenarios that can lead to data breaches in the cloud and a means of assessing the use of potential mitigation strategies to reduce such breaches.
Description: © 2016 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.
Version: Accepted for publication
DOI: 10.1109/CloudCom.2015.58
URI: https://dspace.lboro.ac.uk/2134/21437
Publisher Link: http://dx.doi.org/10.1109/CloudCom.2015.58
ISBN: 9781467395601
Appears in Collections:Conference Papers (Loughborough University London)

Files associated with this item:

File Description SizeFormat
CloudCom_2015_submission_98.pdfAccepted version182.14 kBAdobe PDFView/Open


SFX Query

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.