Title
Spiral^SRA: A Threat-Specific Security Risk Assessment Framework for the Cloud
Abstract
Conventional security risk assessment approaches for cloud infrastructures do not explicitly consider risk with respect to specific threats. This is a challenge for a cloud provider because it may apply the same risk assessment approach in assessing the risk of all of its clients. In practice, the threats faced by each client may vary depending on their security requirements. The cloud provider may also apply generic mitigation strategies that are not guaranteed to be effective in thwarting specific threats for different clients. This paper proposes a threat-specific risk assessment framework which evaluates the risk with respect to specific threats by considering only those threats that are relevant to a particular cloud client. The risk assessment process is divided into three phases which have inter-related activities arranged in a spiral. Application of the framework to a cloud deployment case study shows that considering risk with respect to specific threats leads to a more accurate quantification of security risk. Although our framework is motivated by risk assessment challenges in the cloud it can be applied in any network environment.
Year
DOI
Venue
2018
10.1109/QRS.2018.00049
2018 IEEE International Conference on Software Quality, Reliability and Security (QRS)
Keywords
DocType
ISBN
Security Threats,Security Requirements,Risk Assessment,Risk Evaluation,Threat Specific Risk,Vulnerabilities,Cloud Computing,Security Requirements Elicitation,Security Requirements Analysis,Security Controls,Security Objectives,Security Goals,Threat Specific Countermeasures
Conference
978-1-5386-7758-2
Citations 
PageRank 
References 
0
0.34
31
Authors
6
Name
Order
Citations
PageRank
Armstrong Nhlabatsi1255.65
Jin B. Hong212017.50
Dong Seong Kim386693.34
Rachael Fernandez400.68
Noora Fetais532.76
Khaled M. Khan629529.63