XML-based technologies like the Web Services stack of specifications
have shaped the way e-commerce was performed during the last decade.
Now, with the ongoing move of data and applications to the cloud, the
investigation of these technologies in terms of security and reliability
becomes an inevitable challenge for both cloud providers and cloud
adopters, to prevent catastrophic exploitation incidents. Hence, in the
research area of Web Service security, the ClaWSLab focuses on analyzing
and fostering security guarantees in terms of Web Services usage in
cloud computing scenarios.
(read more)
One of the main concerns of customers is Cloud security and the threat of the unknown.
A seldomly discussed, but in this regard highly relevant open issue is the ability to perform digital investigations. Due to the decentralized nature of data processing in the Cloud, traditional
approaches to evidence collection and recovery are no longer practical. Hence, further research has to be done to mitigate this issue.
(read more)
Cloud Security and Web Application Security are far from being unrelated.
Many Cloud control interfaces are driven or supported by browser based
control panels. Thus vulnerabilities in browser based Cloud control panels
such as Cross Site Scripting, Cross Site Request Forgery or similar can have
vast impact on the overall Cloud security.
(read more)