Visible to the public SLA-Based Secure Cloud Application Development: The SPECS Framework

TitleSLA-Based Secure Cloud Application Development: The SPECS Framework
Publication TypeConference Paper
Year of Publication2015
AuthorsCasola, V., Benedictis, A. D., Rak, M., Villano, U.
Conference Name2015 17th International Symposium on Symbolic and Numeric Algorithms for Scientific Computing (SYNASC)
Date Publishedsep
KeywordsAPI, application program interfaces, cloud computing, Context, contracts, Monitoring, pubcrawl170112, Secure Cloud Application Development, secure Web server, security, security of data, security service level agreement, security SLA, security-as-a-service, security-enhanced service, SLA-based secure cloud application development, SPECS, SPECS framework, Supply chains, Unified modeling language, user-defined security feature
Abstract

The perception of lack of control over resources deployed in the cloud may represent one of the critical factors for an organization to decide to cloudify or not their own services. Furthermore, in spite of the idea of offering security-as-a-service, the development of secure cloud applications requires security skills that can slow down the adoption of the cloud for nonexpert users. In the recent years, the concept of Security Service Level Agreements (Security SLA) is assuming a key role in the provisioning of cloud resources. This paper presents the SPECS framework, which enables the development of secure cloud applications covered by a Security SLA. The SPECS framework offers APIs to manage the whole Security SLA life cycle and provides all the functionalities needed to automatize the enforcement of proper security mechanisms and to monitor userdefined security features. The development process of SPECS applications offering security-enhanced services is illustrated, presenting as a real-world case study the provisioning of a secure web server.

DOI10.1109/SYNASC.2015.59
Citation Keycasola_sla-based_2015