{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,25]],"date-time":"2026-01-25T06:51:53Z","timestamp":1769323913425,"version":"3.49.0"},"publisher-location":"Singapore","reference-count":44,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789811982842","type":"print"},{"value":"9789811982859","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,12,10]],"date-time":"2022-12-10T00:00:00Z","timestamp":1670630400000},"content-version":"vor","delay-in-days":343,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>With the continuous growth of enterprises\u2019 digital transformation, business-driven cloud computing has seen tremendous growth. The security community has proposed a large body of technical mechanisms, operational processes, and practical solutions to achieve cloud security. In addition, diverse jurisdictions also present regulatory requirements on data protection to mitigate possible risks, for instance, unauthorized access, data leakage, sensitive information and privacy disclosure. In view of this, several practical standards, frameworks, and best practices in the industry are proposed to evaluate and improve the protection level of cloud data. However, few evaluation models can conduct a comprehensive quantitative evaluation for cloud data protection that includes security, privacy, and even ethical considerations. In this paper, we first make a comprehensive review of cloud data security and privacy issues, especially also including ethical concerns that we consider as a type of specific risks caused by human factors, which refers to acting honorably, honestly, justly, and legally, due diligence, and due care. Then, we propose a novel evaluation model for cloud data protection that can quantitatively assess the protection level. Finally, based on the parallel evaluation between manual assessment by experts and our evaluation model, results show that our evaluation model is consistent with the manual evaluation conclusion.<\/jats:p>","DOI":"10.1007\/978-981-19-8285-9_4","type":"book-chapter","created":{"date-parts":[[2022,12,9]],"date-time":"2022-12-09T20:02:48Z","timestamp":1670616168000},"page":"51-69","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Considerations on\u00a0Evaluation of\u00a0Practical Cloud Data Protection"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7480-2004","authenticated-orcid":false,"given":"Rui","family":"Mei","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Han-Bing","family":"Yan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yongqiang","family":"He","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qinqin","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shengqiang","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Weiping","family":"Wen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,12,10]]},"reference":[{"issue":"4","key":"4_CR1","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3214303","volume":"51","author":"A Acar","year":"2018","unstructured":"Acar, A., Aksu, H., Uluagac, A.S., Conti, M.: A survey on homomorphic encryption schemes: theory and implementation. ACM Comput. Surv. (CSUR) 51(4), 1\u201335 (2018)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"4_CR2","doi-asserted-by":"crossref","unstructured":"Achmadi, D., Suryanto, Y., Ramli, K.: On developing information security management system (isms) framework for ISO 27001-based data center. In: 2018 International Workshop on Big Data and Information Security (IWBIS), pp. 149\u2013157. IEEE (2018)","DOI":"10.1109\/IWBIS.2018.8471700"},{"key":"4_CR3","series-title":"Lecture Notes in Networks and Systems","doi-asserted-by":"publisher","first-page":"325","DOI":"10.1007\/978-981-16-0882-7_27","volume-title":"Information and Communication Technology for Competitive Strategies (ICTCS 2020)","author":"S Ahmad","year":"2021","unstructured":"Ahmad, S., Mehfuz, S., Beg, J.: Enhancing security of cloud platform with cloud access security broker. In: Kaiser, M.S., Xie, J., Rathore, V.S. (eds.) Information and Communication Technology for Competitive Strategies (ICTCS 2020). LNNS, vol. 190, pp. 325\u2013335. Springer, Singapore (2021). https:\/\/doi.org\/10.1007\/978-981-16-0882-7_27"},{"key":"4_CR4","doi-asserted-by":"crossref","unstructured":"Al-shammari, M.M., Alwan, A.A.: Disaster recovery and business continuity for database services in multi-cloud. In: 2018 1st International Conference on Computer Applications & Information Security (ICCAIS), pp. 1\u20138. IEEE (2018)","DOI":"10.1109\/CAIS.2018.8442005"},{"key":"4_CR5","doi-asserted-by":"crossref","unstructured":"Arafat, M.: Information security management system challenges within a cloud computing environment. In: Proceedings of the 2nd International Conference on Future Networks and Distributed Systems, pp. 1\u20136 (2018)","DOI":"10.1145\/3231053.3231127"},{"key":"4_CR6","series-title":"Lecture Notes on Data Engineering and Communications Technologies","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1007\/978-981-16-3961-6_9","volume-title":"Cyber Security and Digital Forensics","author":"P Bajaj","year":"2022","unstructured":"Bajaj, P., Arora, R., Khurana, M., Mahajan, S.: Cloud security: the future of data storage. In: Khanna, K., Estrela, V.V., Rodrigues, J.J.P.C. (eds.) Cyber Security and Digital Forensics. LNDECT, vol. 73, pp. 87\u201398. Springer, Singapore (2022). https:\/\/doi.org\/10.1007\/978-981-16-3961-6_9"},{"key":"4_CR7","doi-asserted-by":"crossref","unstructured":"Barrowclough, J.P., Asif, R.: Securing cloud hypervisors: a survey of the threats, vulnerabilities, and countermeasures. In: Security and Communication Networks 2018 (2018)","DOI":"10.1155\/2018\/1681908"},{"key":"4_CR8","doi-asserted-by":"crossref","unstructured":"Chen, W.Y., Yu, M., Sun, C.: Architecture and building the medical image anonymization service: cloud, big data and automation. In: 2021 International Conference on Electronic Communications, Internet of Things and Big Data (ICEIB), pp. 149\u2013153. IEEE (2021)","DOI":"10.1109\/ICEIB53692.2021.9686426"},{"key":"4_CR9","unstructured":"Cloud Security Alliance (CSA): Cloud Controls Matrix (CCM). https:\/\/cloudsecurityalliance.org\/research\/cloud-controls-matrix\/"},{"key":"4_CR10","unstructured":"Coalfire: Cloud Security Intelligence Report. https:\/\/www.coalfire.com\/Documents\/Whitepapers\/Securealities-Cloud-Security-Report"},{"key":"4_CR11","unstructured":"Council, P.S.S.: Payment Card Industry Data Security Standard. https:\/\/www.pcisecuritystandards.org\/"},{"issue":"4","key":"4_CR12","first-page":"4","volume":"2","author":"S Dahake","year":"2021","unstructured":"Dahake, S., Chirchi, E.: Maintaining security of the data over cloud: a review. Int. J. Recent Adv. Multidiscipl. Top. 2(4), 4\u201311 (2021)","journal-title":"Int. J. Recent Adv. Multidiscipl. Top."},{"key":"4_CR13","doi-asserted-by":"publisher","first-page":"1153","DOI":"10.1016\/j.procs.2015.05.150","volume":"52","author":"NS Darwazeh","year":"2015","unstructured":"Darwazeh, N.S., Al-Qassas, R.S., AlDosari, F., et al.: A secure cloud computing model based on data classification. Proc. Comput. Sci. 52, 1153\u20131158 (2015)","journal-title":"Proc. Comput. Sci."},{"key":"4_CR14","unstructured":"Deloitte: Data privacy in the cloud: Navigating the new privacy regime in a cloud environment. https:\/\/www2.deloitte.com\/content\/dam\/Deloitte\/ca\/Documents\/risk\/ca-en-risk-privacy-in-the-cloud-pov.PDF"},{"key":"4_CR15","doi-asserted-by":"crossref","unstructured":"Deochake, S., Channapattan, V.: Identity and access management framework for multi-tenant resources in hybrid cloud computing. arXiv preprint arXiv:2203.11463 (2022)","DOI":"10.1145\/3538969.3544896"},{"key":"4_CR16","unstructured":"Dotson, C.: Practical Cloud Security: A Guide For Secure Design and Deployment. O\u2019Reilly Media, Sebastopol (2019)"},{"key":"4_CR17","unstructured":"Fernandez, R.C., Abedjan, Z., Koko, F., Yuan, G., Madden, S., Stonebraker, M.: Aurum: a data discovery system. In: 2018 IEEE 34th International Conference on Data Engineering (ICDE), pp. 1001\u20131012. IEEE (2018)"},{"key":"4_CR18","unstructured":"Fife, L., Kraus, A., Lewis, B.: The Official (ISC)$$^2$$ CCSP CBK Reference. John Wiley & Sons, New York (2021)"},{"key":"4_CR19","unstructured":"FIRST: Common vulnerability scoring system v3.0: Specification document. https:\/\/www.first.org\/cvss\/specification-document"},{"key":"4_CR20","unstructured":"Fortinet: Cloud Security Report. https:\/\/www.fortinet.com\/content\/dam\/fortinet\/assets\/analyst-reports\/ar-cybersecurity-cloud-security.pdf"},{"key":"4_CR21","series-title":"Lecture Notes in Networks and Systems","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1007\/978-3-030-79757-7_3","volume-title":"Recent Advances in Information and Communication Technology 2021","author":"S Fugkeaw","year":"2021","unstructured":"Fugkeaw, S., Worapaluk, K., Tuekla, A., Namkeatsakul, S.: Design and development of a dynamic and efficient PII data loss prevention system. In: Meesad, P., Sodsee, S., Jitsakul, W., Tangwannawit, S. (eds.) IC2IT 2021. LNNS, vol. 251, pp. 23\u201333. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-79757-7_3"},{"key":"4_CR22","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1016\/j.comnet.2019.05.015","volume":"160","author":"H Gunleifsen","year":"2019","unstructured":"Gunleifsen, H., Kemmerich, T., Gkioulos, V.: Dynamic setup of IPSEC VPNS in service function chaining. Comput. Netw. 160, 77\u201391 (2019)","journal-title":"Comput. Netw."},{"key":"4_CR23","doi-asserted-by":"crossref","unstructured":"Hussain, A., Kiah, M.L.M., Anuar, N.B., Md Noor, R., Ahmad, M.: Performance and security challenges digital rights management (DRM) approaches using fog computing for data provenance: a survey. J. Med. Imaging Health Inform. 10(10), 2404\u20132420 (2020)","DOI":"10.1166\/jmihi.2020.3178"},{"key":"4_CR24","unstructured":"International Standards Organization\/International Electrotechnical Commission: ISO\/IEC 17789:2014 Information technology - Cloud computing - Reference architecture. https:\/\/www.iso.org\/standard\/60545.html"},{"key":"4_CR25","unstructured":"(ISC)$$^2$$: Cloud Security Report 2021. https:\/\/www.isc2.org\/-\/media\/ISC2\/Research\/Resource-Thumbnails\/Resource-Center\/Research\/2021-Cloud-Security-Report-FINAL.ashx"},{"key":"4_CR26","series-title":"Advances in Intelligent Systems and Computing","doi-asserted-by":"publisher","first-page":"250","DOI":"10.1007\/978-3-319-67618-0_23","volume-title":"Cybernetics Approaches in Intelligent Systems","author":"L Kacha","year":"2018","unstructured":"Kacha, L., Zitouni, A.: An overview on data security in cloud computing. In: Silhavy, R., Silhavy, P., Prokopova, Z. (eds.) CoMeSySo 2017. AISC, vol. 661, pp. 250\u2013261. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-67618-0_23"},{"key":"4_CR27","doi-asserted-by":"publisher","first-page":"6410180","DOI":"10.1155\/2018\/6410180","volume":"2018","author":"H Ko","year":"2018","unstructured":"Ko, H., M\u011bs\u00ed\u010dek, L., Choi, J., Hwang, S.: A study on secure medical-contents strategies with DRM based on cloud computing. J. Healthcare Eng. 2018, 6410180 (2018)","journal-title":"J. Healthcare Eng."},{"issue":"2","key":"4_CR28","first-page":"16","volume":"10","author":"S Krishnan","year":"2019","unstructured":"Krishnan, S., Neyaz, A., Shashidhar, N.: A survey of security and forensic features in popular eDiscovery software suites. International Journal of Security (IJS) 10(2), 16 (2019)","journal-title":"International Journal of Security (IJS)"},{"key":"4_CR29","unstructured":"Kutame, F.N., Ochara, N.M., Kadyamatimba, A., Sotnikov, A., Fiodorov, I., Telnov, Y.: A case study of cloud-based business continuity model. In: CEUR Workshop Proceedings, pp. 26\u201335 (2021)"},{"issue":"7","key":"4_CR30","doi-asserted-by":"publisher","first-page":"578","DOI":"10.1016\/j.cose.2004.06.013","volume":"23","author":"J Lopez","year":"2004","unstructured":"Lopez, J., Oppliger, R., Pernul, G.: Authentication and authorization infrastructures (AAIS): a comparative survey. Comput. Secur. 23(7), 578\u2013590 (2004)","journal-title":"Comput. Secur."},{"key":"4_CR31","doi-asserted-by":"crossref","unstructured":"Madavi, K.B., Karthick, P.V.: Enhanced cloud security using cryptography and steganography techniques. In: 2021 International Conference on Disruptive Technologies for Multi-Disciplinary Research and Applications (CENTCON), vol. 1, pp. 90\u201395. IEEE (2021)","DOI":"10.1109\/CENTCON52345.2021.9687919"},{"key":"4_CR32","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"252","DOI":"10.1007\/978-3-030-89137-4_18","volume-title":"Science of Cyber Security","author":"R Mei","year":"2021","unstructured":"Mei, R., Yan, H.-B., Han, Z.-H.: RansomLens: understanding ransomware via causality analysis on system provenance graph. In: Lu, W., Sun, K., Yung, M., Liu, F. (eds.) SciSec 2021. LNCS, vol. 13005, pp. 252\u2013267. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-89137-4_18"},{"key":"4_CR33","doi-asserted-by":"crossref","unstructured":"Mei, R., Yan, H.B., Han, Z.H., Jiang, J.C.: CTScopy: hunting cyber threats within enterprise via provenance graph-based analysis. In: 2021 IEEE 21st International Conference on Software Quality, Reliability and Security (QRS), pp. 28\u201339. IEEE (2021)","DOI":"10.1109\/QRS54544.2021.00014"},{"key":"4_CR34","doi-asserted-by":"publisher","first-page":"102","DOI":"10.23919\/JCC.2022.00.028","volume":"19","author":"R Mei","year":"2022","unstructured":"Mei, R., Yan, H., Wang, Q., Han, Z., Lyu, Z.: TDLens: toward an empirical evaluation of provenance graph-based approach to cyber threat detection. China Commun. 19, 102\u2013115 (2022)","journal-title":"China Commun."},{"key":"4_CR35","unstructured":"MITRE: CAPEC: Common Attack Pattern Enumeration and Classification. https:\/\/capec.mitre.org\/index.html"},{"key":"4_CR36","unstructured":"Parliament, E.: General Data Protection Regulation. https:\/\/gdpr-info.eu\/"},{"key":"4_CR37","series-title":"Smart Innovation, Systems and Technologies","doi-asserted-by":"publisher","first-page":"439","DOI":"10.1007\/978-981-13-9282-5_42","volume-title":"Smart Intelligent Computing and Applications","author":"S Patil","year":"2020","unstructured":"Patil, S., Joshi, S., Patil, D.: Enhanced privacy preservation using anonymization in IOT-enabled smart homes. In: Satapathy, S.C., Bhateja, V., Mohanty, J.R., Udgata, S.K. (eds.) Smart Intelligent Computing and Applications. SIST, vol. 159, pp. 439\u2013454. Springer, Singapore (2020). https:\/\/doi.org\/10.1007\/978-981-13-9282-5_42"},{"key":"4_CR38","doi-asserted-by":"crossref","unstructured":"Shukla, M.K., Dubey, A.K., Upadhyay, D., Novikov, B.: Group key management in cloud for shared media sanitization. In: 2020 Sixth International Conference on Parallel, Distributed and Grid Computing (PDGC), pp. 117\u2013120. IEEE (2020)","DOI":"10.1109\/PDGC50313.2020.9315325"},{"key":"4_CR39","doi-asserted-by":"publisher","unstructured":"Srivastava, P., Choudhary, A.: Evolving evidence gathering process: cloud forensics. In: Tiwari, S., Suryani, E., Ng, A.K., Mishra, K.K., Singh, N. (eds.) Proceedings of International Conference on Big Data, Machine Learning and their Applications. LNNS, vol. 150, pp. 227\u2013243. Springer, Singapore (2021). https:\/\/doi.org\/10.1007\/978-981-15-8377-3_20","DOI":"10.1007\/978-981-15-8377-3_20"},{"key":"4_CR40","unstructured":"du Toit, J.: Digital rights management to protect private data on the internet. In: ECCWS 2018 17th European Conference on Cyber Warfare and Security V2, p. 128. Academic Conferences and Publishing Limited (2018)"},{"key":"4_CR41","doi-asserted-by":"crossref","unstructured":"Wang, Q., Yan, H., Han, Z.: Explainable apt attribution for malware using NLP techniques. In: 2021 IEEE 21st International Conference on Software Quality, Reliability and Security (QRS), pp. 70\u201380. IEEE (2021)","DOI":"10.1109\/QRS54544.2021.00018"},{"key":"4_CR42","doi-asserted-by":"publisher","first-page":"131723","DOI":"10.1109\/ACCESS.2020.3009876","volume":"8","author":"P Yang","year":"2020","unstructured":"Yang, P., Xiong, N., Ren, J.: Data security and privacy protection for cloud storage: a survey. IEEE Access 8, 131723\u2013131740 (2020)","journal-title":"IEEE Access"},{"key":"4_CR43","doi-asserted-by":"publisher","first-page":"18209","DOI":"10.1109\/ACCESS.2018.2820162","volume":"6","author":"J Zhang","year":"2018","unstructured":"Zhang, J., Chen, B., Zhao, Y., Cheng, X., Hu, F.: Data security and privacy-preserving in edge computing paradigm: survey and open issues. IEEE Access 6, 18209\u201318237 (2018)","journal-title":"IEEE Access"},{"key":"4_CR44","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1109\/TIFS.2020.3004264","volume":"16","author":"Z Zhang","year":"2020","unstructured":"Zhang, Z., Cheng, Y., Gao, Y., Nepal, S., Liu, D., Zou, Y.: Detecting hardware-assisted virtualization with inconspicuous features. IEEE Trans. Inf. Forensics Secur. 16, 16\u201327 (2020)","journal-title":"IEEE Trans. Inf. Forensics Secur."}],"container-title":["Communications in Computer and Information Science","Cyber Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-19-8285-9_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,24]],"date-time":"2022-12-24T00:02:47Z","timestamp":1671840167000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-19-8285-9_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9789811982842","9789811982859"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-981-19-8285-9_4","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"value":"1865-0929","type":"print"},{"value":"1865-0937","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"10 December 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CNCERT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China Cyber Security Annual Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Beijing","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 August 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 August 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"cncert2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/conf.cert.org.cn","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}