期刊文献+

基于SecSLA的云供应商选择方法 被引量:2

Cloud Provider Selection Method Based on SecSLA
下载PDF
导出
摘要 当前云计算服务水平协议通常只关注性能,缺乏安全参数,并且客户需要在多家云供应商中做出选择。针对上述问题,提出一种基于SecSLA的云供应商选择方法。构建云计算安全服务水平协议(SecSLA)的指标体系,采用目标-问题-度量方法形成SecSLA的50个底层评估指标项。并将改进的ELECTRE方法引入到云供应商的选择决策过程中,结合净优势值与净劣势值的思想,简化决策过程。实例计算与分析结果表明,SecSLA较全面地覆盖了云计算事故处理、漏洞补丁管理、合规性与可用性等因素,该云供应商选择方法能消除传统选择消去法ELECTRE Ⅱ的繁琐与对经验的依赖,便于实现编程自动化处理,且最终的评价结果与ELECTRE Ⅱ、灰色关联、理想解法一致。 The cloud computing service level agreement often only focuses on performance while seldom emphasizes security parameters. Besides, customers are confused by several suppliers in cloud computing market. Therefore, cloud computing Security Service Level Agreement(SecSLA) with detailed indexes is put forward and an improved ELECTRE method is introduced to the cloud provider selection process. Goal-Questi0n-Metric method is employed to form 50 bottom evaluation indexes for SecSLA. The modified ELECTRE method combines the value of net advantage and net disadvantage to simplify the decision process.The calculation and analysis of instance prove the following aspects: the proposed SecSLA has a relatively comprehensive coverage of the cloud computing assessment factors, such as incident handling, vulnerability and patch management, compliance and availability; the suggested method eliminates the redundancy and dependence on experience of ELECTRE II, which makes the realization of automatic process easier. The final evaluation order conforms to the result of ELECTRE II, gray correlation method and TOPSIS method, which indicates that the designed method can play a guiding role in the selection of cloud service provider.
出处 《计算机工程》 CAS CSCD 2013年第10期1-5,共5页 Computer Engineering
基金 国家科技支撑计划基金资助项目(2012BAH14B02) 国家发改委信息安全专项基金资助项目(发改办高技[2012]1424号)
关键词 云计算 安全服务水平协议 云供应商选择 目标-问题-度量方法 ELECTRE方法 cloud computing Security Service Level Agreement(SecSLA) cloud provider selection Goal-Question-Metric(GQM)method Elimination Et Choice Translating Reality(ELECTRE) method
  • 相关文献

参考文献13

  • 1Dekker M, Hogben G. Survey and Analysis of Security Parameters in Cloud SLAs Across the European Public Sector[R]. Heraklion, Greece: European Network and Infor- mation Security Agency, Tech. Rep.: TR-201 I- 12-21, 201 I.
  • 2Herming R R. Security Service Level Agreements: Quantifiable Security for the Enterprise?[C]//Proceedings of the Workshop on New Security Paradigms. New York, USA: ACM Press, 2000.
  • 3de Chaves S A, Westphall C B, Lamin F R. SLA Perspective in Security Management for Cloud Computing[C]// Proceedings of .the 6th International Conference on Net- working and Services. Cancun, Mexican: IEEE Press, 2010.
  • 4Bemsmed K, Jaatun M G, Meland P H, et al. Security SLAs for Federated Cloud Services[C]//Proceedings of the 6th International Conference on Availability, Reliability and Security. Vienna, Austria: IEEE Press, 2011.
  • 5Luna J, Ghani H, Vateva T, et al. Quantitative Assessment of Cloud Security Level Agreements----A Case Study[C]// Proceedings of the International Conference on Security and Cryptography. Rome, Italy: Is. n.], 2012.
  • 6Putri N R, Mganga M C. Enhancing Information Security in Cloud Computing Services Using SLA Based Metrics[D]. Karlskrona, Sweden: Blekinge Institute of Technology, 2011.
  • 7孙守明.模糊环境下ELECTRE之研究[D].中国台湾,台中:东海大学工业工程研究所,1999.
  • 8Fenton N E, Pfleeger S L. Software Metrics: A Rigorous and Practical Approach[M]. Boston, USA: PWS Publishing Co., 1998.
  • 9Hogben C Dekker M. A Guide to Monitoring of Security Service Levels in Cloud Contracts[R]. Heraklion, Greece: European Network and Information Security Agency, Tech. Rep.: TR-2012-04-02, 2012.
  • 10Piliero S. The CIS Security Metrics vl.0.0[EB/OL]. (2010- 11-01). https://benchrnarks.cisecurity.org/tools2/metrics/CIS_ Security Metrics_vl.l.0.pdf.

二级参考文献8

  • 1Jose Figueira, Bernard Roy. ,Determining the weights of criteria in the ELECTRE type methods with a revised Simos procedure [J]. European Journal of Operational Research,2002, 139:317- 326.
  • 2孙守明.模糊环境下ELECTRE之研究[D].东海大学工业工程研究所硕士论文,1999.
  • 3Mohamed Rami Mahmoud, Luis, A. Garcia. Comparison of different multicriteria evaluation methods for the Red Bluff diversion dam [J]. Environmental Modelling & Software,2000,15:471-478.
  • 4Hobbs, B.F., Chankong, V., Hamadeh, W., Stakhiv, E.,Does choice of multicriteria method matter? An experiment in water resources planning [J]. Water Resources Research 28(7): 1767- 1779.
  • 5HWANG C L,masud a multiple objective decision making methods and applictions [M]. springer verlag ,N.Y., 1979.
  • 6朱茵,孟志勇,阚叔愚.新建铁路方案比选的理论与方法[J].铁道工程报,1992(2).
  • 7江晖.浅谈排除选择法在水电工程招标决策中的应用[J].水电能源科学,2000,18(3):35-37. 被引量:4
  • 8吴小萍,詹振炎.消去与选择转换法优选线路方案[J].铁道学报,2000,22(4):68-72. 被引量:12

共引文献23

同被引文献4

引证文献2

二级引证文献3

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部