Authors:
Bruno M. Barros
1
;
Leonardo H. Iwaya
2
;
Marcos A. Simplício Jr.
1
;
Tereza C. M. B. Carvalho
1
;
András Méhes
3
and
Mats Näslund
3
Affiliations:
1
Universidade de São Paulo, Brazil
;
2
Universidade de São Paulo and Karlstad University, Brazil
;
3
Ericsson Research, Sweden
Keyword(s):
Cloud Networking, Cloud Security, Security Threats, Security Taxonomy.
Related
Ontology
Subjects/Areas/Topics:
Cloud Computing
;
Cloud Computing Enabling Technology
;
Cloud Risk, Challenges, and Governance
;
Fundamentals
;
Security, Privacy, and Compliance Management
Abstract:
A central component of managing risks in cloud computing is to understand the nature of security threats. The
relevance of security concerns are evidenced by the efforts from both the academic community and technological
organizations such as NIST, ENISA and CSA, to investigate security threats and vulnerabilities related to
cloud systems. Provisioning secure virtual networks (SVNs) in a multi-tenant environment is a fundamental
aspect to ensure trust in public cloud systems and to encourage their adoption. However, comparing existing
SVN-oriented solutions is a difficult task due to the lack of studies summarizing the main concerns of network
virtualization and providing a comprehensive list of threats those solutions should cover. To address this issue,
this paper presents a threat classification for cloud networking, describing threat categories and attack scenarios
that should be taken into account when designing, comparing, or categorizing solutions. The classification
is based
on the CSA threat report, building upon studies and surveys from the specialized literature to extend
the CSA list of threats and to allow a more detailed analysis of cloud network virtualization issues.
(More)