Security by Design for Big Data Frameworks over Cloud Computing

Cloud deployment architectures have become a preferable computation model of Big Data (BD) operations. Their scalability, flexibility, and cost-effectiveness motivated this trend. In a such deployment model, the data are no longer physically maintained under the user’s direct control, which raises n...

ver descrição completa

Detalhes bibliográficos
Autores: Awaysheh, Feras M., Aladwan, Mohammad N., Alazab, Mamoun, Alawadi, Sadi, Cabaleiro Domínguez, José Carlos, Fernández Pena, Anselmo Tomás
Formato: artículo
Fecha de publicación:2022
País:España
Recursos:Universidad de Santiago de Compostela (USC)
Repositorio:Minerva. Repositorio Institucional de la Universidad de Santiago de Compostela
Idioma:inglés
OAI Identifier:oai:minerva.usc.gal:10347/42121
Acesso em linha:https://hdl.handle.net/10347/42121
Access Level:acceso abierto
Palavra-chave:Big data (BD)
Cloud-computing security
Data protection
Reference architecture
Security analysis pattern
Security components diagram
Security-by-design
Descrição
Resumo:Cloud deployment architectures have become a preferable computation model of Big Data (BD) operations. Their scalability, flexibility, and cost-effectiveness motivated this trend. In a such deployment model, the data are no longer physically maintained under the user’s direct control, which raises new security concerns. In this context, BD security plays a decisive role in the widespread adoption of cloud architectures. However, it is challenging to develop a comprehensive security plan unless it is based on a preliminary analysis that ensures a realistic secure assembly and addresses domain-specific vulnerabilities. This article presents a novel security-by-design framework for BD frameworks deployment over cloud computing (BigCloud). In particular, it relies on a systematic security analysis methodology and a completely automated security assessment framework. Our framework enables the mapping of BigCloud security domain knowledge to the best practices in the design phase. We validated the proposed framework by implementing an Apache Hadoop stack use case. The study findings demonstrate its effectiveness in improving awareness of security aspects and reducing security design time. It also evaluates the strengths and limitations of the proposed framework, from which it highlights the main existing and open challenges in the BigCloud-related area.