Evidence-based security configurations for cloud datastores

Published: 03 April 2017 Publication History


Cloud systems offer a diversity of security mechanisms with potentially complex configuration options. So far, security engineering has focused on achievable security levels, but not on the costs associated with a specific security mechanism and its configuration. Through a series of experiments with a variety of cloud datastores conducted over the last years, we gained substantial knowledge on how one desired quality like security can have a significant impact on other system qualities like performance. In this paper, we report on select findings related to security-performance trade-offs for three prominent cloud datastores, focusing on data in transit encryption, and propose a simple, structured approach for making trade-off decisions based on factual evidence gained through experimentation. Our approach allows to rationally reason about security trade-offs.


SAC '17: Proceedings of the Symposium on Applied Computing
April 2017
2004 pages
Publication History

Published: 03 April 2017


Author Tags

  1. cloud storage
  2. data in transit security
  3. performance benchmarking
  4. security configurations
  5. trade-offs


SAC 2017
SAC 2017: Symposium on Applied Computing
April 3 - 7, 2017
Marrakech, Morocco

