Back to Search Start Over

Security and Privacy Service Level Agreement composition for Internet of Things systems on top of standard controls.

Authors :
Rios, Erkuden
Higuero, Mariví
Larrucea, Xabier
Rak, Massimiliano
Casola, Valentina
Iturbe, Eider
Source :
Computers & Electrical Engineering. Mar2022, Vol. 98, pN.PAG-N.PAG. 1p.
Publication Year :
2022

Abstract

• This paper proposes a solution to obtain the security and privacy levels that can be granted by Cloud-based IoT critical infrastructures, such as healthcare systems composed of multiple components in Cloud and IoT devices. • Particularly, this paper presents a methodology to compose Security Service Level Agreements (SecSLAs) and Privacy SLAs (PLAs) of Cloud-based IoT applications on top of standard controls, which aid in the formalization and assessment of the security and privacy levels of these composite applications. • The methodology includes a technique to quantitatively compute the Service Level Objectives (SLO) of the controls declared in the Composed SLA, based on the SLOs granted by individual components. • The method relies on the analysis of the relationships between the application components and the security controls implementation. For each component a preliminary SLA template is built, based on security self-assessment techniques. • Finally, the paper presents the validation of the methodology showing the creation of the SecSLAs and PLAs of a real multiCloud-based IoT application in the eHealth domain. The growing markets of Cloud services and IoT platforms have dramatically raised system flexibility and deployment options. However, increasing complexity and dependency on third-party providers make it difficult to assess the security and privacy levels that distributed systems can offer to their users. In the last years, machine-readable Service Level Agreements (SLAs) have been studied as an optimal method for copying with security and privacy policies. Still, the computation of the SLAs of applications distributed in diverse infrastructures remains a challenging task. This paper presents a methodology to compose security SLAs (SecSLAs) and privacy SLAs (PLAs) of Cloud-based IoT applications on top of standard controls. The composition considers individual components' SLAs and the control delegation relationships between the components with respect to different types of controls (common, system-specific or hybrid controls). Furthermore, we propose a technique to calculate the Service Level Objectives (SLO) of the controls declared in the composite SLA based on the SLOs granted by individual components. Finally, the paper presents the validation of the methodology carried out to create the SecSLAs and PLAs of a real multiCloud-based IoT application in the eHealth domain. [Display omitted] [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
00457906
Volume :
98
Database :
Academic Search Index
Journal :
Computers & Electrical Engineering
Publication Type :
Academic Journal
Accession number :
155150540
Full Text :
https://doi.org/10.1016/j.compeleceng.2022.107690