Threat-oriented security framework in risk management using multiagent system

被引:12
|
作者
Bedi, Punam [1 ]
Gandotra, Vandana [1 ]
Singhal, Archana [1 ]
Narang, Himanshi [1 ]
Sharma, Sumit [1 ]
机构
[1] Univ Delhi, Dept Comp Sci, Delhi 110007, India
来源
SOFTWARE-PRACTICE & EXPERIENCE | 2013年 / 43卷 / 09期
关键词
threat-oriented security model; research honeytokens; statistical model; proactive risk management; multiagent system planning; meta-agents; fuzzy logic;
D O I
10.1002/spe.2133
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Present day sophisticated and innovative attacks have resulted in exponentially increasing security problems. This paper therefore presents a three-phased threat-oriented security model to meet the above security challenges as a part of proactive risk management. This model is based on a spiral process for software development because it is a risk driven approach and provides an incremental method for a progressively growing system with decreasing risk. Integration of threat management during the development process in the proposed work provides necessary security cover against both unforeseen and known threats. Identification of these threats has been made possible by fusion of a threat modeling process and research honeytokens in conjunction with a statistical model in the first phase. Necessary security measures to mitigate the above identified threats have been adopted in the second phase using multiagent system planning. Risk reduction as a result of adoption of countermeasures has been evaluated in the third phase using meta-agents in association with fuzzy logic in a multiagent environment. The proposed proactive measures of this model have been demonstrated with a case study on 'Online Banking' to show its feasibility and has been implemented using Java Agent Development Environment, Apache Tomcat Server, with MySQL Server at the backend. Copyright (C) 2012 John Wiley & Sons, Ltd.
引用
收藏
页码:1013 / 1038
页数:26
相关论文
共 50 条
  • [1] Threat-Oriented Security Framework: A Proactive Approach in Threat Management
    Gandotra, Vandana
    Singhal, Archana
    Bedi, Punam
    [J]. 2ND INTERNATIONAL CONFERENCE ON COMPUTER, COMMUNICATION, CONTROL AND INFORMATION TECHNOLOGY (C3IT-2012), 2012, 4 : 487 - 494
  • [2] A Novel Differential Evolution Algorithm for Threat-Oriented Weapon System Planning
    Liu, Can
    Ge, Bingfeng
    Yang, Kewei
    Jiang, Jiang
    Li, Mengjun
    [J]. 2015 9TH ANNUAL IEEE INTERNATIONAL SYSTEMS CONFERENCE (SYSCON), 2015, : 614 - 619
  • [3] Multiagent Security Evaluation Framework for Service Oriented Architecture Systems
    Kolaczek, Grzegorz
    [J]. KNOWLEDGE-BASED AND INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS, PT I, PROCEEDINGS, 2009, 5711 : 30 - 37
  • [4] Security Incidents Management System Based on Multiagent Systems
    Aguilar, Jose
    Abraham, Blanca
    [J]. PROCEEDINGS OF THE 13TH WSEAS INTERNATIONAL CONFERENCE ON COMPUTERS, 2009, : 90 - +
  • [5] Developing a multiagent conference management system using the O-MaSE process framework
    DeLoach, Scott A.
    [J]. AGENT-ORIENTED SOFTWARE ENGINEERING VIII, 2008, 4951 : 168 - 181
  • [6] Big Data Management System Security Threat Model
    Poltavtseva, M. A.
    Zegzhda, D. P.
    Kalinin, M. O.
    [J]. AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2019, 53 (08) : 903 - 913
  • [7] Big Data Management System Security Threat Model
    M. A. Poltavtseva
    D. P. Zegzhda
    M. O. Kalinin
    [J]. Automatic Control and Computer Sciences, 2019, 53 : 903 - 913
  • [8] SpiralSRA: A Threat-Specific Security Risk Assessment Framework for the Cloud
    Nhlabatsi, Armstrong
    Hong, Jin B.
    Kim, Dong Seong
    Fernandez, Rachael
    Fetais, Noora
    Khan, Khaled M.
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY (QRS 2018), 2018, : 367 - 374
  • [9] IT Security Risk Management: An Early Assessment Framework
    Sinclaire, Jollean K.
    Simon, Judith C.
    Campbell, Charles J.
    Wilkes, Ronald B.
    [J]. JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2011, 6 (04): : 248 - 261
  • [10] Real-Time Framework for Energy Management System of a Smart Microgrid Using Multiagent Systems
    Netto, Roberto S.
    Ramalho, Guilherme R.
    Bonatto, Benedito D.
    Carpinteiro, Otavio A. S.
    Zambroni de Souza, A. C.
    Oliveira, Denisson Q.
    Braga, Rodrigo A. S.
    [J]. ENERGIES, 2018, 11 (03)