A comparative study of the evolution of vulnerabilities in IT systems and its relation to the new concept of cloud computing

Purpose - The purpose of this paper is to classify and categorize the vulnerability types emerged with time as information technology (IT) systems evolved. This comparative study aims to compare the seriousness of the old well-known vulnerabilities that may still exist with lower possibility of happ...

وصف كامل

محفوظ في:
التفاصيل البيبلوغرافية
المؤلف الرئيسي: Kouatli, Issam (author)
التنسيق: article
منشور في: 2014
الوصول للمادة أونلاين:http://hdl.handle.net/10725/3700
http://dx.doi.org/10.1108/JMH-02-2014-0018
http://libraries.lau.edu.lb/research/laur/terms-of-use/articles.php
http://www.emeraldinsight.com/doi/full/10.1108/JMH-02-2014-0018
الوسوم: إضافة وسم
لا توجد وسوم, كن أول من يضع وسما على هذه التسجيلة!
_version_ 1864513462059663360
author Kouatli, Issam
author_facet Kouatli, Issam
author_role author
dc.creator.none.fl_str_mv Kouatli, Issam
dc.date.none.fl_str_mv 2014
2016-05-06T13:02:17Z
2016-05-06T13:02:17Z
2016-05-06
dc.identifier.none.fl_str_mv 1751-1348
http://hdl.handle.net/10725/3700
http://dx.doi.org/10.1108/JMH-02-2014-0018
Kouatli, I. (2014). A comparative study of the evolution of vulnerabilities in IT systems and its relation to the new concept of cloud computing. Journal of Management History, 20(4), 409-433.
http://libraries.lau.edu.lb/research/laur/terms-of-use/articles.php
http://www.emeraldinsight.com/doi/full/10.1108/JMH-02-2014-0018
dc.language.none.fl_str_mv en
dc.relation.none.fl_str_mv Journal of Management History
dc.rights.*.fl_str_mv info:eu-repo/semantics/openAccess
dc.title.none.fl_str_mv A comparative study of the evolution of vulnerabilities in IT systems and its relation to the new concept of cloud computing
dc.type.none.fl_str_mv Article
info:eu-repo/semantics/publishedVersion
info:eu-repo/semantics/article
description Purpose - The purpose of this paper is to classify and categorize the vulnerability types emerged with time as information technology (IT) systems evolved. This comparative study aims to compare the seriousness of the old well-known vulnerabilities that may still exist with lower possibility of happening with that of new technologies like cloud computing with Mobility access. Cloud computing is a new structure of IT that is becoming the main part of the new model of business environment. However, issues regarding such new hype of technology do not come without obstacles. These issues have to be addressed before full acceptability of cloud services in a globalized business environment. Businesses need to be aware of issues of concerns before joining the cloud services. This paper also highlights these issues and shows the comparison table to help businesses with appropriate decision-making when joining the cloud. Design/methodology/approach – A historical review of emerged vulnerabilities as IT systems evolved was conducted, then these vulnerabilities were categorized into eight different categories, each of which composed of multiple vulnerability types. Simple scoring techniques were used to build a “risk” analysis table where each vulnerability type was given a score based on availability of matured solution and the likeliness of happening, then in case of vulnerability type, another score was used to derive the impact of such vulnerability. The resulted weighted score can be derived from the multiplication of likeliness to happen score with that of its impact in case it did happen. Percentage of seriousness represented by the percentage of the derived weighted score of each of the vulnerabilities can then be concluded. Similar table was developed for issues related to cloud computing environment in specific. Findings – After surveying the historical background of IT systems and emerged vulnerabilities as well as reviewing the common malicious types of system vulnerabilities, this paper identifies 22 different types of vulnerability categorized in eight different categories. This comparative study explores amount of possible vulnerabilities in new technology like cloud computing services. Specific issues for cloud computing were also explored and a similar comparative study was developed on these issues. The result of the comparative study between all types of vulnerabilities since the start of IT system development till today’s technology of cloud computing, shows that the highest percentage vulnerability category was the one related to mobility access as mobile applications/systems are relatively newly emerged and do not have a matured security solution(s). Practical implications – Learning from history, one can conclude the current risk factor in dealing with new technology like cloud computing. Businesses can realize that decision to join the cloud requires thinking about the issues mentioned in this paper and identifying the most vulnerability types to try to avoid them. Originality/value – A new comparative study and new classification of vulnerabilities demonstrated with risk analysis using simple scoring technique.
eu_rights_str_mv openAccess
format article
id LAURepo_2f8a4718b7d7b40a882c7076b44ac342
identifier_str_mv 1751-1348
Kouatli, I. (2014). A comparative study of the evolution of vulnerabilities in IT systems and its relation to the new concept of cloud computing. Journal of Management History, 20(4), 409-433.
language_invalid_str_mv en
network_acronym_str LAURepo
network_name_str Lebanese American University repository
oai_identifier_str oai:laur.lau.edu.lb:10725/3700
publishDate 2014
repository.mail.fl_str_mv
repository.name.fl_str_mv
repository_id_str
spelling A comparative study of the evolution of vulnerabilities in IT systems and its relation to the new concept of cloud computingKouatli, IssamPurpose - The purpose of this paper is to classify and categorize the vulnerability types emerged with time as information technology (IT) systems evolved. This comparative study aims to compare the seriousness of the old well-known vulnerabilities that may still exist with lower possibility of happening with that of new technologies like cloud computing with Mobility access. Cloud computing is a new structure of IT that is becoming the main part of the new model of business environment. However, issues regarding such new hype of technology do not come without obstacles. These issues have to be addressed before full acceptability of cloud services in a globalized business environment. Businesses need to be aware of issues of concerns before joining the cloud services. This paper also highlights these issues and shows the comparison table to help businesses with appropriate decision-making when joining the cloud. Design/methodology/approach – A historical review of emerged vulnerabilities as IT systems evolved was conducted, then these vulnerabilities were categorized into eight different categories, each of which composed of multiple vulnerability types. Simple scoring techniques were used to build a “risk” analysis table where each vulnerability type was given a score based on availability of matured solution and the likeliness of happening, then in case of vulnerability type, another score was used to derive the impact of such vulnerability. The resulted weighted score can be derived from the multiplication of likeliness to happen score with that of its impact in case it did happen. Percentage of seriousness represented by the percentage of the derived weighted score of each of the vulnerabilities can then be concluded. Similar table was developed for issues related to cloud computing environment in specific. Findings – After surveying the historical background of IT systems and emerged vulnerabilities as well as reviewing the common malicious types of system vulnerabilities, this paper identifies 22 different types of vulnerability categorized in eight different categories. This comparative study explores amount of possible vulnerabilities in new technology like cloud computing services. Specific issues for cloud computing were also explored and a similar comparative study was developed on these issues. The result of the comparative study between all types of vulnerabilities since the start of IT system development till today’s technology of cloud computing, shows that the highest percentage vulnerability category was the one related to mobility access as mobile applications/systems are relatively newly emerged and do not have a matured security solution(s). Practical implications – Learning from history, one can conclude the current risk factor in dealing with new technology like cloud computing. Businesses can realize that decision to join the cloud requires thinking about the issues mentioned in this paper and identifying the most vulnerability types to try to avoid them. Originality/value – A new comparative study and new classification of vulnerabilities demonstrated with risk analysis using simple scoring technique.PublishedN/A2016-05-06T13:02:17Z2016-05-06T13:02:17Z20142016-05-06Articleinfo:eu-repo/semantics/publishedVersioninfo:eu-repo/semantics/article1751-1348http://hdl.handle.net/10725/3700http://dx.doi.org/10.1108/JMH-02-2014-0018Kouatli, I. (2014). A comparative study of the evolution of vulnerabilities in IT systems and its relation to the new concept of cloud computing. Journal of Management History, 20(4), 409-433.http://libraries.lau.edu.lb/research/laur/terms-of-use/articles.phphttp://www.emeraldinsight.com/doi/full/10.1108/JMH-02-2014-0018enJournal of Management Historyinfo:eu-repo/semantics/openAccessoai:laur.lau.edu.lb:10725/37002021-03-19T09:10:04Z
spellingShingle A comparative study of the evolution of vulnerabilities in IT systems and its relation to the new concept of cloud computing
Kouatli, Issam
status_str publishedVersion
title A comparative study of the evolution of vulnerabilities in IT systems and its relation to the new concept of cloud computing
title_full A comparative study of the evolution of vulnerabilities in IT systems and its relation to the new concept of cloud computing
title_fullStr A comparative study of the evolution of vulnerabilities in IT systems and its relation to the new concept of cloud computing
title_full_unstemmed A comparative study of the evolution of vulnerabilities in IT systems and its relation to the new concept of cloud computing
title_short A comparative study of the evolution of vulnerabilities in IT systems and its relation to the new concept of cloud computing
title_sort A comparative study of the evolution of vulnerabilities in IT systems and its relation to the new concept of cloud computing
url http://hdl.handle.net/10725/3700
http://dx.doi.org/10.1108/JMH-02-2014-0018
http://libraries.lau.edu.lb/research/laur/terms-of-use/articles.php
http://www.emeraldinsight.com/doi/full/10.1108/JMH-02-2014-0018