[论文解读] Systematic Mapping Study On Security Threats in Cloud Computing
本系统映射研究基于云安全联盟的《云计算十大威胁》框架,分析了105篇关于云安全威胁的出版物。研究识别出最常被研究的威胁,将其映射至15个安全领域,并发现以合规为重点的解决方案最为普遍,其中数据泄露和不安全接口是研究最集中的问题。
Today, Cloud Computing is rising strongly, presenting itself to the market by its main service models, known as IaaS, PaaS and SaaS, that offer advantages in operational investments by means of on-demand costs, where consumers pay by resources used. In face of this growth, security threats also rise, compromising the Confidentiality, Integrity and Availability of the services provided. Our work is a Systematic Mapping where we hope to present metrics about publications available in literature that deal with some of the seven security threats in Cloud Computing, based in the guide entitled "Top Threats to Cloud Computing" from the Cloud Security Alliance (CSA). In our research we identified the more explored threats, distributed the results between fifteen Security Domains and identified the types of solutions proposed for the threats. In face of those results, we highlight the publications that are concerned to fulfill some standard of compliance.
研究动机与目标
- 使用系统映射方法分析云安全威胁研究的现状。
- 识别云安全联盟框架中七个主要云威胁里,在学术文献中被最常研究的威胁。
- 按安全领域对出版物进行分类,并评估所提出的解决方案类型。
- 评估现有研究在多大程度上关注云安全中的合规标准。
提出的方法
- 在学术数据库中使用预定义的搜索标准开展系统性文献综述。
- 采用云安全联盟的《云计算十大威胁》作为威胁分类的参考框架。
- 将每篇出版物映射至一个或多个预定义的15个安全领域(例如,访问控制、数据安全)。
- 将所提出的解决方案分类为技术控制、基于策略的机制或以合规为重点的方法等类型。
- 量化每种威胁和每个安全领域下的出版物频率,以识别研究趋势。
- 采用结构化的数据提取协议,以确保分析的一致性并减少偏差。
实验结果
研究问题
- RQ1在学术文献中,云安全联盟的七个云安全威胁中,哪一个被最频繁地讨论?
- RQ2出版物在云计算中定义的15个安全领域中如何分布?
- RQ3为缓解已识别威胁而最常提出的解决方案类型是什么?
- RQ4现有研究在多大程度上聚焦于安全标准的合规性?
- RQ5是否存在特定威胁或安全领域在研究覆盖上存在空白?
主要发现
- 被研究最多的威胁是“A1:不安全的接口和应用程序编程接口(API)”,其次是“A2:数据丢失或泄露”。
- “数据安全”领域是代表性最强的,其出版物数量最高。
- 以合规为重点的解决方案是所提出缓解措施中最普遍的类型,在大量研究中均有出现。
- 与内部人员攻击和尽职调查不足相关的威胁在文献中代表性不足。
- 仅有少数研究涉及“A7:账户或服务失效”和“A8:未知或未管理的攻击面”等威胁。
- 该映射揭示出研究存在强烈的偏向于技术控制和标准合规性的倾向,而对组织或流程层面控制的探索则较为有限。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。