A security reference architecture for cloud systems

  • Authors:
  • Eduardo B. Fernandez;Raul Monge

  • Affiliations:
  • Universidad Tecnica Federico Santa Maria, Valparaiso, Chile;Universidad Tecnica Federico Santa Maria, Valparaiso, Chile

  • Venue:
  • Proceedings of the WICSA 2014 Companion Volume
  • Year:
  • 2014

Quantified Score

Hi-index 0.00

Visualization

Abstract

Security is a fundamental concern in clouds and several cloud vendors provide Security Reference Architectures (SRAs) to describe the security level of their services. A SRA is an abstract architecture without implementation details showing a conceptual model of security for a cloud system. In general, Reference Architectures (RAs) are becoming useful tools to understand and build complex systems. We propose here a Security Reference Architecture (SRA), defined using UML models and patterns, incorporating a specific approach to build secure systems. We present a metamodel and possible patterns to conceptualize the approach. We also describe some uses for this SRA, including its value for Service Level Agreements (SLAs), service certification, monitoring, and security evaluation. We show this latter use in some detail.