Application of security reference architecture to Big Data ecosystems in an industrial scenario

Big Data environments are typically very complex ecosystems; this means that implementing them is complicated. One possible technique with which to address this complexity is the use of abstraction. Reference architecture (RA) can be useful for an improved understanding of the main components of Big...

Descripción completa

Detalles Bibliográficos
Autores: Moreno García-Nieto, Julio, Gómez Rodríguez, Javier, Serrano Martín, Manuel Ángel, Fernández, Eduardo B., Fernandez-Medina, Eduardo
Tipo de recurso: artículo
Fecha de publicación:2020
País:España
Institución:Universidad de Castilla-La Mancha
Repositorio:RUIdeRA. Repositorio Institucional de la UCLM
OAI Identifier:oai:ruidera.uclm.es:10578/25937
Acceso en línea:https://doi.org/10.1002/spe.2829
http://hdl.handle.net/10578/25937
Access Level:acceso abierto
Palabra clave:Big Data
Case study
Security patterns
Security reference architecture
Descripción
Sumario:Big Data environments are typically very complex ecosystems; this means that implementing them is complicated. One possible technique with which to address this complexity is the use of abstraction. Reference architecture (RA) can be useful for an improved understanding of the main components of Big Data. Herein, we propose a security RA that includes the management of security concerns and provides the main elements of a Big Data ecosystem. Application of this architecture to real-world scenarios facilitates its refinement and improves its usefulness. In this article, we present a case study of a real-world Big Data ecosystem implemented in a banking environment. This ecosystem was developed by everis, an NTT company with which we collaborated for this study. To conduct this validation case study, a map was established between the elements of the Big Data ecosystem implemented and our proposal. Consequently, a series of valuable lessons that can improve both our architecture and the security of the Big Data environment were obtained. These include recommendations for a set of best practices such as the use of security patterns.