Back to Search
Start Over
Matchmaking semantic security policies in heterogeneous clouds
- Source :
- Future Generation Computer Systems. 55:176-185
- Publication Year :
- 2016
- Publisher :
- Elsevier BV, 2016.
-
Abstract
- The adoption of the cloud paradigm to access IT resources and services has posed many security issues which need to be cared of. Security becomes even a much bigger concern when services built on top of many commercial clouds have to interoperate. Among others, the value of the service delivered to end customers is strongly affected by the security of network which providers are able to build in typical SOA contexts. Currently, every provider advertises its own security strategy by means of proprietary policies, which are sometimes ambiguous and very often address the security problem from a non-uniform perspective. Even policies expressed in standardized languages do not appear to fit a dynamic scenario like the SOA's, where services need to be sought and composed on the fly in a way that is compatible with the end-to-end security requirements. We then propose an approach that leverages on the semantic technology to enrich standardized security policies with an ad-hoc content. The semantic annotation of policies enables machine reasoning which is then used for both the discovery and the composition of security-enabled services. In the presented approach the semantic enrichment of policies is enforced by an automatic procedure. We further developed a semantic framework capable of matchmaking in a smart way security capabilities of providers and security requirements of customers, and tested it on a use case scenario. Semantic matchmaking of security policies in cloud environments.Security ontology for modeling security concepts.Automatic semantic annotation of WS-SecurityPolicy policies.
- Subjects :
- Computer Networks and Communications
Computer science
Interoperability
Cloud computing
02 engineering and technology
Security policy
Computer security
computer.software_genre
Logical security
Security information and event management
World Wide Web
Security engineering
0202 electrical engineering, electronic engineering, information engineering
semantics
Cloud computing security
Ontology
business.industry
security policie
cloud computing
020206 networking & telecommunications
Computer security model
security policies
Security service
Hardware and Architecture
Information security standards
Software security assurance
semantic
Security through obscurity
Human-computer interaction in information security
Semantic technology
Network security policy
020201 artificial intelligence & image processing
business
computer
Software
Subjects
Details
- ISSN :
- 0167739X
- Volume :
- 55
- Database :
- OpenAIRE
- Journal :
- Future Generation Computer Systems
- Accession number :
- edsair.doi.dedup.....baf77eabe9d10806bb70ad79e8d21c55