透過您的圖書館登入
IP:18.119.248.54

摘要


雲端運算(Cloud Computing)透過網際網路的連結,透過大型資訊平台佈署及提供資訊服務,但雲端上商業資料可能成為網路攻擊的目標,故如何消除企業對雲端運算服務(cloud services)之資安的疑慮,使企業對網際網路資料中心(Internet Data Center, IDC)的資訊安全管理產生信心,是導入雲端運算的重要事務。若企業忽視雲端運算服務的資訊風險,將可能造成隱私資訊外洩並嚴重影響商譽。因此,企業須要有一套營運風險分析方法,系統化評選IDC 所提出的解決方案;現有風險分析方法較適用於資訊資產個別威脅事件為基礎之風險分析,面對雲端運算作業採用分散式服務架構,須分析多重網路攻擊事件間之交互影響,故本風險模式改以資訊資產之作業流程為基礎,運用模糊派翠網(Fuzzy Petri Net, FPN)理論完整分析作業的威脅流程,估算資產之各項作業的風險,將原有風險分析導入動態運作環境,搭配ISO/IEC 27001之資訊安全管控,系統化分析資訊資產的風險。最後舉一雲端運算服務平台風險分析為例,說明所研提的方法,探討案例中分散式佈署及資訊更新時所帶來的風險。

並列摘要


Cloud computing adopts the Internet to deliver information services to open networks via deployment of large scale of platforms, in which commercial data on the clouds might become targets of network attacks. How to eliminate the worries about information security on cloud services, raise the confidences on information security management of IDC is a crucial issue in cloud computing. It might lead to disclosure of confidential information and serious damage to business reputation, if enterprises neglected assessing the risks of cloud services. Thus, enterprises need systemically assess the operational risks with the proposals of IDC by comparing distinct cloud provider solutions, when decided to adopt the cloud services. Available risk models are more suitable for assessing the risk of information assets based on a series of specific threat events. It is necessary to adjust the risk model to effectively assess the risks of cloud services via analyzing the effects of multiple interleaved attacks from the view of asset operation flow perspective. Therefore, a fuzzy risk assessment model is proposed to evaluate the risks of cloud security in a dynamic environment using Fuzzy Petri Net (FPN) by adopting ISO/IEC 27001 standard. Finally, an illustration case of risk assessment of cloud services in Internet Data Center (IDC) is given to demonstrate our approach. From numerical illustrations, our approach effectively outranks the risks of cloud services, especially when they are deployed and updated their information in a distributed deployment.

參考文獻


溫鳳祺(2003)。ISO/IEC Guide 73: 2002(E/F)風險管理─詞彙─標準使用指引。資訊安全論壇。11,33-40。
資策會(2010),「未採用雲端服務 資訊安全是疑慮」,(取得日期:2010年8月8日),[available at http://www.itis.tw/node/4135]。
劉永禮、陳啟光(2002)。以BS7799資訊安全管理規範建構組織資訊安全風險管理模式之研究(碩士論文)。元智大學工業工程與管理學系。
羅濟群、王平、趙國銘(2006)。模糊群體決策環境下以OWA運算子進行風險評估。資管評論。14,1-21。
Brodkin J. (2008), “Gartner: Seven Cloud-Computing Security Risks”, Network World, (accessed Jan 14, 2010), [available at http://www.networkworld.com/news/2008/070208-cloud.html].

被引用紀錄


樊鈺承(2011)。企業決策支援平台的設計與實現〔碩士論文,崑山科技大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0025-1502201118200800
張郁琪(2013)。探討第四方物流BPO雲端服務企業接受度之研究〔碩士論文,國立臺北科技大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0006-2307201311032600
董仲瑋(2014)。以資服業經理人的角度探討雲端的資訊治理〔碩士論文,國立中正大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0033-2110201613571359

延伸閱讀