Towards incident handling in the cloud: challenges and approaches

  • Authors:
  • Bernd Grobauer;Thomas Schreck

  • Affiliations:
  • Siemens CERT, Munich, Germany;Siemens CERT, Munich, Germany

  • Venue:
  • Proceedings of the 2010 ACM workshop on Cloud computing security workshop
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Security incident handling, an integral part of security management, treats detection and analysis of security incidents as well as the subsequent response (i.e., containment, eradication, and recovery.) Existing processes and methods for incident handling are geared towards infrastructures and operational models that will be increasingly outdated by cloud computing. This paper examines, how the changes introduced by cloud computing influence the incident handling process. It identifies problems that cloud customers encounter in each of the incident handling steps and provides possible approaches and corresponding challenges. The identified approaches provide guidance for cloud customers and cloud service providers towards effective incident handling in the cloud; the identified challenges may serve as basis for a research agenda in cloud incident handling.