SLA-Based Secure Cloud Application Development: The SPECS Framework
Title | SLA-Based Secure Cloud Application Development: The SPECS Framework |
Publication Type | Conference Paper |
Year of Publication | 2015 |
Authors | Casola, V., Benedictis, A. D., Rak, M., Villano, U. |
Conference Name | 2015 17th International Symposium on Symbolic and Numeric Algorithms for Scientific Computing (SYNASC) |
Date Published | sep |
Keywords | API, application program interfaces, cloud computing, Context, contracts, Monitoring, pubcrawl170112, Secure Cloud Application Development, secure Web server, security, security of data, security service level agreement, security SLA, security-as-a-service, security-enhanced service, SLA-based secure cloud application development, SPECS, SPECS framework, Supply chains, Unified modeling language, user-defined security feature |
Abstract | The perception of lack of control over resources deployed in the cloud may represent one of the critical factors for an organization to decide to cloudify or not their own services. Furthermore, in spite of the idea of offering security-as-a-service, the development of secure cloud applications requires security skills that can slow down the adoption of the cloud for nonexpert users. In the recent years, the concept of Security Service Level Agreements (Security SLA) is assuming a key role in the provisioning of cloud resources. This paper presents the SPECS framework, which enables the development of secure cloud applications covered by a Security SLA. The SPECS framework offers APIs to manage the whole Security SLA life cycle and provides all the functionalities needed to automatize the enforcement of proper security mechanisms and to monitor userdefined security features. The development process of SPECS applications offering security-enhanced services is illustrated, presenting as a real-world case study the provisioning of a secure web server. |
DOI | 10.1109/SYNASC.2015.59 |
Citation Key | casola_sla-based_2015 |
- security of data
- user-defined security feature
- Unified modeling language
- supply chains
- SPECS framework
- SPECS
- SLA-based secure cloud application development
- security-enhanced service
- security-as-a-service
- security SLA
- security service level agreement
- API
- security
- secure Web server
- Secure Cloud Application Development
- pubcrawl170112
- Monitoring
- contracts
- Context
- Cloud Computing
- application program interfaces