An Integrated Meta-model for Cloud Application Security Modelling

https://doi.org/10.1016/j.procs.2016.08.283Get rights and content
Under a Creative Commons license
open access

Abstract

Model-driven engineering (MDE) promises to automate the cloud application management phases, including deployment and adaptive provisioning. However, most MDE approaches neglect the security aspect even if it is considered the number one factor for not migrating to the cloud. As such, this paper proposes a security meta-model that a cloud-based MDE approach can exploit to become security-aware. This meta-model captures both high- and low-level security requirements and capabilities to drive application deployment as well security-oriented scalability rules to guide application re-configuration. It is also coupled with OCL constraints enforcing the security domain semantics. A method for creating re-usable security elements facilitating rapid security model specification conforming to the meta-model is also proposed, to reduce the designer's modelling effort.

Keywords

cloud
security
control
DSL
meta-model
model
requirements
scalability
rules
metrics

Cited by (0)

Peer-review under responsibility of organizing committee of the international conference on cloud forward: From Distributed to Complete Computing.