Authors:
            
                    Erkuden Rios
                    
                        
                                1
                            
                    
                    ; 
                
                    Eider Iturbe
                    
                        
                                1
                            
                    
                    ; 
                
                    Leire Orue-Echevarria
                    
                        
                                1
                            
                    
                    ; 
                
                    Massimiliano Rak
                    
                        
                                2
                            
                    
                     and
                
                    Valentina Casola
                    
                        
                                3
                            
                    
                    
                
        
        
            Affiliations:
            
                    
                        
                                1
                            
                    
                    TECNALIA, Spain
                
                    ; 
                
                    
                        
                                2
                            
                    
                    Second University of Napoli, Italy
                
                    ; 
                
                    
                        
                                3
                            
                    
                    University of Naples Federico II, Italy
                
        
        
        
        
        
             Keyword(s):
            Multi-cloud, Security-by-design, Cloud SLAs, QoSec, Distributed Deployment, DevOps.
        
        
            
                Related
                    Ontology
                    Subjects/Areas/Topics:
                
                        Cloud Computing
                    ; 
                        Cloud Computing Enabling Technology
                    ; 
                        Fundamentals
                    ; 
                        Monitoring of Services, Quality of Service, Service Level Agreements
                    ; 
                        QoS for Applications on Clouds
                    ; 
                        Security, Privacy, and Compliance Management
                    
            
        
        
            
                Abstract: 
                The most challenging applications in heterogeneous cloud ecosystems are those that are able to maximise
the benefits of the combination of the cloud resources in use: multi-cloud applications. They have to deal
with the security of the individual components as well as with the overall application security including the
communications and the data flow between the components. In this paper we present a novel approach
currently in progress, the MUSA framework. The MUSA framework aims to support the security-intelligent
lifecycle management of distributed applications over heterogeneous cloud resources. The framework
includes security-by-design mechanisms to allow application self-protection at runtime, as well as methods
and tools for the integrated security assurance in both the engineering and operation of multi-cloud
applications. The MUSA framework leverages security-by-design, agile and DevOps approaches to enable
the security-aware development and operation of multi-cloud applica
                tions.
                (More)