Cloud Security Issues

Проблемы безопасности облачных вычислений
Balachandra Reddy Kandukuri, Ramakrishna Paturi V., Atanu Rakshit
2009-01-01

Software as a Service (SaaS)cloud computing securitydata confidentialitysecurity standardizationservice level agreements (SLA)
In past three decades, the world of computation has changed from centralized (client-server not web-based) to distributed systems and now we are getting back to the virtual centralization (Cloud Computing). Location of data and processes makes the difference in the realm of computation. On one hand, an individual has full control on data and processes in his/her computer. On the other hand, we have the cloud computing wherein, the service and data maintenance is provided by some vendor which leaves the client/customer unaware of where the processes are running or where the data is stored. So, logically speaking, the client has no control over it. The cloud computing uses the internet as the communication media. When we look at the security of data in the cloud computing, the vendor has to provide some assurance in service level agreements (SLA) to convince the customer on security issues. Organizations use cloud computing as a service infrastructure, critically like to examine the security and confidentiality issues for their business critical insensitive applications. Yet, guaranteeing the security of corporate data in the "cloud" is difficult, if not impossible, as they provide different services like Software as a service (SaaS), Platform as a service (PaaS), and Infrastructure as a service (IaaS). Each service has their own security issues. So the SLA has to describe different levels of security and their complexity based on the services to make the customer understand the security policies that are being implemented. There has to be a standardized way to prepare the SLA irrespective to the providers. This can help some of the enterprises to look forward in using the cloud services. In this paper, we put forward some security issues that have to be included in SLA.
1
A standardized SLA framework independent of cloud providers could improve enterprise understanding and adoption of cloud services.
2
Cloud computing reduces customers’ direct control because vendors manage data storage and process locations on their behalf.
3
Each cloud service model introduces distinct security issues that must be addressed separately.
4
Guaranteeing corporate data security and confidentiality in cloud environments is difficult across SaaS, PaaS, and IaaS offerings.
5
Service-level agreements should specify security policies, protection levels, and complexities according to the particular cloud service provided.

cloud computing services and their service-level agreements (SLAs)

security and confidentiality requirements and issues that should be specified and standardized in SLAs across SaaS, PaaS, and IaaS

Publication Details
Publication Date
2009-01-01
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Balachandra Reddy Kandukuri
Ramakrishna Paturi V.
Atanu Rakshit
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%