The increasing complexity of modern information technology infrastructures poses new challenges for cyber risk assessment, especially when the boundaries of resources and computing extend across multiple administrative domains and heterogeneous environments, such as those found in the cloud continuum. Traditional frameworks fall short in these dynamic, multi-domain contexts. In this work, we propose a holistic approach that combines trust assessment through continuous monitoring of platform health indicators and service-level security assessment into a comprehensive cyber risk model for quantitative scoring. Our framework leverages a multi-layer architecture featuring automated data collection, semantic enrichment, and advanced risk metrics. It supports intra- and inter-layer anomaly detection and is validated on an experimental, cloud continuum-like deployment spanning multiple administrative domains and mixing physical and virtual environments. Results show that our method outperforms isolated approaches, offering enhanced detection, contextual explanation of threats, and improved risk visibility across the cloud continuum.

Holistic Cyber Risk Assessment in the Cloud Continuum: A Multi-Layer, Multi-Domain Approach / Gatti, Gabriele; Valero, José María Jorquera; Pérez, Manuel Gil; Basile, Cataldo. - In: IEEE ACCESS. - ISSN 2169-3536. - 13:(2025), pp. 180593-180612. [10.1109/access.2025.3622915]

Holistic Cyber Risk Assessment in the Cloud Continuum: A Multi-Layer, Multi-Domain Approach

Gatti, Gabriele;Basile, Cataldo
2025

Abstract

The increasing complexity of modern information technology infrastructures poses new challenges for cyber risk assessment, especially when the boundaries of resources and computing extend across multiple administrative domains and heterogeneous environments, such as those found in the cloud continuum. Traditional frameworks fall short in these dynamic, multi-domain contexts. In this work, we propose a holistic approach that combines trust assessment through continuous monitoring of platform health indicators and service-level security assessment into a comprehensive cyber risk model for quantitative scoring. Our framework leverages a multi-layer architecture featuring automated data collection, semantic enrichment, and advanced risk metrics. It supports intra- and inter-layer anomaly detection and is validated on an experimental, cloud continuum-like deployment spanning multiple administrative domains and mixing physical and virtual environments. Results show that our method outperforms isolated approaches, offering enhanced detection, contextual explanation of threats, and improved risk visibility across the cloud continuum.
2025
File in questo prodotto:
File Dimensione Formato  
Holistic_Cyber_Risk_Assessment_in_the_Cloud_Continuum_A_Multi-Layer_Multi-Domain_Approach.pdf

accesso aperto

Tipologia: 2a Post-print versione editoriale / Version of Record
Licenza: Creative commons
Dimensione 2.52 MB
Formato Adobe PDF
2.52 MB Adobe PDF Visualizza/Apri
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11583/3004472