Making Cloud SLAs readily usable in the EU private sector

SLA Monitoring

In IT the term monitoring is an overloaded one. Most of the monitoring techniques that already exist are focused on the monitoring of performance indicators, as shown by Keller et al. in [1], Grabner, Ganglia, and Nagios. DeSVi [2], [3] include SLAaware functionalities. Monitoring has also become relevant in the cloud context (for example, the Amazon’s CloudWatch.

The mOSAIC project focuses on missing monitoring capabilities in this case for multi cloud environments. If we focus on security monitoring, we can see that there is no consensus about what security monitoring should cover and for what. Approaches in the area of continuous monitoring for detection of intrusion and malicious attacks for Web Service Providers or Cloud environment are presented by Brower in [4], Lazarevic et al. [5] and Spanoudakis et al. [6].

SPECS is trying to assess a monitoring infrastructure for security parameters included in a security SLA, thus detecting violations and promoting enforcement activities to improve security. Security monitoring can be deployed across all capabilities, and users, not only the providers that own that responsibility. This is case of federated clouds (Clayman et al. [7]) where the monitoring infrastructure developed adapts automatically to changes in the monitoring capabilities that are available in service based systems running on clouds, following dynamic SLA monitoring checks (Foster et al. [8], [9]). The Lattice monitoring system [10] provides also support for monitoring dynamically changing cloud federations.

Finally, NIST’s SCAP specifications and Cloud Security Alliance’s Cloud Trust Protocol provide interfaces for extracting monitoring data from clouds. In the case of the CTP, the status is still under working group.


