Monshizadeh and Khatri
340
14.5.2 PaaS
1) Layer point of view: This layer is normally used by developers to program and run
their applications. Generating software bug or file system corruption, unauthorized access or privilege upgrade and denial of service are the security threats that
should be considered at this layer. Strong authentication and access right control is
required for this layer to limit the user base that can make critical modification to
configuration. Logging of all management actions are important to trace misbehaving users and to learn from mistakes. Therefore, a policy control mechanism
could evaluate the requested access and decide whether or not to grant the access
to developer.
2) Deployment point of view: This layer will be used by a limited group of professionals
and does not need to be accessed by all end users, therefore community or hybrid
deployment for this layer is recommended. Mobile operators could take advantage
of the public cloud, while for sensitive parts of the system software, they could just
provide a private cloud.
14.5.3 SaaS
1) Layer point of view: Since the application layer is the closest layer to the end users,
they could easily install different kinds of malware or spyware and steal the information or cause data corruption at this layer. Secure protocols and malware detection
methods are some of the prevention mechanisms that should be considered in
this layer.
2) Deployment point of view: In order to gain the initial cloud computing benefits, such
as elasticity and economies of scale, SaaS should be available to all customers (end
users and other tenants), therefore public cloud is recommended for SaaS.
In Figure 14.8, a larger area is dedicated to the IaaS layer, to highlight the higher
security requirement for this layer.
14.6 Future Directions
A cloud system is distributed over many geographically separate computing sites, and if
one site breaks down unexpectedly (e.g. by earthquake or severe cyber‐attack), it is
challenging to leverage such a cloud system. Although there are many researches on the
security concerns of cloud computing, there are still open issues requesting further
investigation in future studies:
1) Various new business opportunities opened by cloudification disruption in the
operator domain should be investigated and analyzed as to whether these business
opportunities trigger further technological breakthroughs or not. On the other hand,
further research is necessary to understand the requirements to TaaS and their
mutual priorities. It should be studied whether there will be lightweight MVNOs,
which operate almost without their own staff. To achieve this, the expectations of
various stakeholders, i.e. MNOs, MVNOs, equipment vendors and end users in the
security domain, should be listed.
Précédent

- 382/483

Suivant