Bayesian Decision Network-Based Security Risk Management Framework

被引:27
|
作者
Khosravi-Farmad, Masoud [1 ]
Ghaemi-Bafghi, Abbas [1 ]
机构
[1] Ferdowsi Univ Mashhad, Dept Comp Engn, Data & Commun Secur Lab, Mashhad, Razavi Khorasan, Iran
关键词
Risk assessment; Risk mitigation; Risk management framework; Cost-benefit analysis; Decision making; Bayesian decision network; ATTACK GRAPH;
D O I
10.1007/s10922-020-09558-5
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network security risk management is comprised of several essential processes, namely risk assessment, risk mitigation and risk validation and monitoring, which should be done accurately to maintain the overall security level of a network in an acceptable level. In this paper, an integrated framework for network security risk management is presented which is based on a probabilistic graphical model called Bayesian decision network (BDN). Using BDN, we model the information needed for managing security risks, such as information about vulnerabilities, risk-reducing countermeasures and the effects of implementing them on vulnerabilities, with the minimum need for expert's knowledge. In order to increase the accuracy of the proposed risk assessment process, vulnerabilities exploitation probability and impact of vulnerabilities exploitation on network assets are calculated using inherent, temporal and environmental factors. In the risk mitigation process, a cost-benefit analysis is efficiently done using modified Bayesian inference algorithms even in case of budget limitation. The experimental results show that network security level enhances significantly due to precise assessment and appropriate mitigation of risks.
引用
收藏
页码:1794 / 1819
页数:26
相关论文
共 50 条
  • [41] Bayesian network-based proactive maintenance
    Muller, A
    Suhner, MC
    Lung, B
    PROBABILISTIC SAFETY ASSESSMENT AND MANAGEMENT, VOL 1- 6, 2004, : 2066 - 2071
  • [42] Bayesian network-based projected clustering
    Zhou, Li-Hua
    Liu, Wei-Yi
    Xu, Yu-Feng
    Chen, I-Iong-Mei
    PROCEEDINGS OF 2008 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, 2008, : 2651 - 2656
  • [43] Network-based sparse Bayesian classification
    Miguel Hernandez-Lobato, Jose
    Hernandez-Lobato, Daniel
    Suarez, Alberto
    PATTERN RECOGNITION, 2011, 44 (04) : 886 - 900
  • [44] A decision model based security risk management approach
    Bhattacharya, Somak
    Ghosh, S. K.
    IMECS 2008: INTERNATIONAL MULTICONFERENCE OF ENGINEERS AND COMPUTER SCIENTISTS, VOLS I AND II, 2008, : 1194 - 1199
  • [45] Bayesian network-based trust model
    Wang, Y
    Vassileva, J
    IEEE/WIC INTERNATIONAL CONFERENCE ON WEB INTELLIGENCE, PROCEEDINGS, 2003, : 372 - 378
  • [46] Sensor Network-based AMI Network Security
    Kim, Jincheol
    Ahn, Seongji
    Kim, Youngeok
    Lee, Kidong
    Kim, Sangjin
    2010 IEEE PES TRANSMISSION AND DISTRIBUTION CONFERENCE AND EXPOSITION: SMART SOLUTIONS FOR A CHANGING WORLD, 2010,
  • [47] Improved Bayesian Network-Based Risk Model and Its Application in Disaster Risk Assessment
    Ming Li
    Mei Hong
    Ren Zhang
    International Journal of Disaster Risk Science, 2018, 9 : 237 - 248
  • [48] Improved Bayesian Network-Based Risk Model and Its Application in Disaster Risk Assessment
    Li, Ming
    Hong, Mei
    Zhang, Ren
    INTERNATIONAL JOURNAL OF DISASTER RISK SCIENCE, 2018, 9 (02) : 237 - 248
  • [49] Improved Bayesian Network-Based Risk Model and Its Application in Disaster Risk Assessment
    Ming Li
    Mei Hong
    Ren Zhang
    InternationalJournalofDisasterRiskScience, 2018, 9 (02) : 237 - 248
  • [50] Neural network-based multi-sensor fusion for security management
    Xiao, DeBao
    Zhou, Ying
    Wei, Meijuan
    2006 1ST IEEE CONFERENCE ON INDUSTRIAL ELECTRONICS AND APPLICATIONS, VOLS 1-3, 2006, : 134 - +