Cristin-resultat-ID: 1641993
Sist endret: 13. desember 2018, 07:20
NVI-rapporteringsår: 2018
Resultat
Vitenskapelig artikkel
2018

Security Incident Information Exchange for Cloud Service Provisioning Chains

Bidragsytere:
  • Christian Frøystad
  • Inger Anne Tøndel og
  • Martin Gilje Jaatun

Tidsskrift

Cryptography
ISSN 2410-387X
e-ISSN 2410-387X
NVI-nivå 1

Om resultatet

Vitenskapelig artikkel
Publiseringsår: 2018
Publisert online: 2018
Volum: 2
Hefte: 4
Artikkelnummer: 41
Open Access

Importkilder

Scopus-ID: 2-s2.0-85102026033

Beskrivelse Beskrivelse

Tittel

Security Incident Information Exchange for Cloud Service Provisioning Chains

Sammendrag

Online services are increasingly becoming a composition of different cloud services, making incident-handling difficult, as Cloud Service Providers (CSPs) with end-user customers need information from other providers about incidents that occur at upstream CSPs to inform their users. In this paper, we argue the need for commonly agreed-upon incident information exchanges between providers to improve accountability of CSPs, and present both such a format and a prototype implementing it. The solution can handle simple incident information natively as well as embed standard representation formats for incident-sharing, such as IODEF and STIX. Preliminary interviews show a desire for such a solution. The discussion considers both technical challenges and non-technical aspects related to improving the situation for incident response in cloud-computing scenarios. Our solution holds the potential of making incident-sharing more efficient

Bidragsytere

Christian Frøystad

  • Tilknyttet:
    Forfatter
    ved Software Engineering, Safety and Security ved SINTEF AS

Inger Anne Tøndel

  • Tilknyttet:
    Forfatter
    ved Software Engineering, Safety and Security ved SINTEF AS
Aktiv cristin-person

Martin Gilje Jaatun

  • Tilknyttet:
    Forfatter
    ved Software Engineering, Safety and Security ved SINTEF AS
1 - 3 av 3