Observational Analyzes of a Cloud Security Framework Through Formal Specification
摘要
Since the advent of cloud computing technology, cloud security continues to be a concern as more organizations migrate to cloud environments. Despite numerous efforts dedicated to addressing cloud security challenges through the development of frameworks, the challenges increase as cloud computing migration progresses. This research paper briefly revisits three specialized cloud security frameworks in the literature and presents a comprehensive cloud security framework (CSF) from previous work by the authors. Following an interpretive and pseudo-positivist philosophy, the new framework is analyzed, and the threat detection manager (TDM) is identified as a critical component. Subsequently, it is studied in further detail by formally specifying its underlying data structures and operations through the Z specification language. Observations are elicited from the specification constructs aimed at enhancing the TDM. Future work in this area is noted as formalizing and enhancing the rest of the framework, followed by surveys among cloud-security practitioners to further enhance and validate the resultant framework, amongst other testing its scalability.