Threat-oriented security framework in risk management using multiagent system

被引:12
|
作者
Bedi, Punam [1 ]
Gandotra, Vandana [1 ]
Singhal, Archana [1 ]
Narang, Himanshi [1 ]
Sharma, Sumit [1 ]
机构
[1] Univ Delhi, Dept Comp Sci, Delhi 110007, India
来源
SOFTWARE-PRACTICE & EXPERIENCE | 2013年 / 43卷 / 09期
关键词
threat-oriented security model; research honeytokens; statistical model; proactive risk management; multiagent system planning; meta-agents; fuzzy logic;
D O I
10.1002/spe.2133
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Present day sophisticated and innovative attacks have resulted in exponentially increasing security problems. This paper therefore presents a three-phased threat-oriented security model to meet the above security challenges as a part of proactive risk management. This model is based on a spiral process for software development because it is a risk driven approach and provides an incremental method for a progressively growing system with decreasing risk. Integration of threat management during the development process in the proposed work provides necessary security cover against both unforeseen and known threats. Identification of these threats has been made possible by fusion of a threat modeling process and research honeytokens in conjunction with a statistical model in the first phase. Necessary security measures to mitigate the above identified threats have been adopted in the second phase using multiagent system planning. Risk reduction as a result of adoption of countermeasures has been evaluated in the third phase using meta-agents in association with fuzzy logic in a multiagent environment. The proposed proactive measures of this model have been demonstrated with a case study on 'Online Banking' to show its feasibility and has been implemented using Java Agent Development Environment, Apache Tomcat Server, with MySQL Server at the backend. Copyright (C) 2012 John Wiley & Sons, Ltd.
引用
收藏
页码:1013 / 1038
页数:26
相关论文
共 50 条
  • [31] A Collaborative Framework for Information Security Management System Using Intelligent Multi-Agent
    Wang Peng
    Xing Li-ning
    [J]. COMPONENTS, PACKAGING AND MANUFACTURING TECHNOLOGY, 2011, 460-461 : 428 - 432
  • [32] An Enhanced Threat Intelligence Driven Hybrid Model for Information Security Risk Management
    Amin, Habib E. L.
    Samhat, Abed Ellatif
    Chamoun, Maroun
    Oueidat, Lina
    Feghali, Antoine
    [J]. PROCEEDINGS 2024 IEEE 25TH INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS, WOWMOM 2024, 2024, : 5 - 12
  • [33] Improvement of Information System Security Risk Management
    Abbass, Wissam
    Baina, Amine
    Bellafkih, Mostafa
    [J]. 2016 4TH IEEE INTERNATIONAL COLLOQUIUM ON INFORMATION SCIENCE AND TECHNOLOGY (CIST), 2016, : 182 - 187
  • [34] Management of security policy configuration using a Semantic Threat Graph approach
    Foley, Simon
    Fitzgerald, William
    [J]. JOURNAL OF COMPUTER SECURITY, 2011, 19 (03) : 567 - 605
  • [35] Risk-driven security testing using risk analysis with threat modeling approach
    Palanivel, Maragathavalli
    Selvadurai, Kanmani
    [J]. SPRINGERPLUS, 2014, 3 : 1 - 14
  • [36] Security Framework using Hbase and Log Management Technology
    Kim, Nan Ju
    Kim, Yu Jin
    Lim, Seul Gi
    Park, Joon Woo
    Choi, Eui In
    [J]. PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON CHEMICAL, MATERIAL AND FOOD ENGINEERING, 2015, 22 : 676 - 679
  • [37] Framework of Personalized Web-oriented Data Management System
    Chen, Hao
    Li, Bing
    [J]. 2009 EIGHTH INTERNATIONAL CONFERENCE ON GRID AND COOPERATIVE COMPUTING, PROCEEDINGS, 2009, : 398 - 400
  • [38] A theoretical framework for the implementation of patient-oriented pharmacy services using a quality management system
    Dolcet, H. Oller
    Benrimoj, S. I.
    Fernandez-Llimos, F.
    [J]. PHARMACY WORLD & SCIENCE, 2007, 29 (06): : 709 - 709
  • [39] A framework of Decision Support System for Quality-Oriented management
    He, WB
    Mu, CD
    Fan, YS
    [J]. 1997 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENT PROCESSING SYSTEMS, VOLS 1 & 2, 1997, : 1551 - 1555
  • [40] AN OBJECT-ORIENTED SECURITY KNOWLEDGE FRAMEWORK FOR THE NUCLEAR SAFETY SYSTEM PROJECT
    Chou, I-Hsin
    Fan, Chin-Feng
    [J]. INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING, 2010, 20 (03) : 347 - 365