Quality of security metrics and measurements

被引:34
|
作者
Savola, Reijo M. [1 ]
机构
[1] VTT Tech Res Ctr Finland, Oulu 90650, Finland
关键词
Security metrics; Security quantification; Quality of security metrics; Expert opinion survey; Security effectiveness;
D O I
10.1016/j.cose.2013.05.002
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Quantification of information security can be used to obtain evidence to support decision-making about the security performance of software systems. Knowledge about the relational importance of the main quality criteria of security metrics can help build security metrology models based on practical needs. This paper presents the results of a quantitative security metrics expert survey of 141 respondents, and an associated interview study, regarding the prioritization of 19 quality criteria of security metrics identified in the literature. The interviews were used to validate the survey results and to obtain further information on the findings. The results identified three foundational quality criteria of security metrics: correctness, measurability, and meaningfulness. These criteria form the basis for credibility and sufficiency for security metrics and associated measurements. Moreover, usability was seen as an important criterion. The paper analyzes the foundational and related quality criteria and proposes a model of them. (c) 2013 Elsevier Ltd. All rights reserved.
引用
收藏
页码:78 / 90
页数:13
相关论文
共 50 条
  • [31] New Measurements Reveal Weaknesses of Image Quality Metrics in Evaluating Graphics Artifacts
    Cadik, Martin
    Herzog, Robert
    Mantiuk, Rafal
    Myszkowski, Karol
    Seidel, Hans-Peter
    [J]. ACM TRANSACTIONS ON GRAPHICS, 2012, 31 (06):
  • [32] Measurements of uncertainty in macrophyte metrics used to assess European lake water quality
    Dudley, Bernard
    Dunbar, Michael
    Penning, Ellis
    Kolada, Agnieszka
    Hellsten, Seppo
    Oggioni, Alessandro
    Bertrin, Vincent
    Ecke, Frauke
    Sondergaard, Martin
    [J]. HYDROBIOLOGIA, 2013, 704 (01) : 179 - 191
  • [33] Measurements of uncertainty in macrophyte metrics used to assess European lake water quality
    Bernard Dudley
    Michael Dunbar
    Ellis Penning
    Agnieszka Kolada
    Seppo Hellsten
    Alessandro Oggioni
    Vincent Bertrin
    Frauke Ecke
    Martin Søndergaard
    [J]. Hydrobiologia, 2013, 704 : 179 - 191
  • [34] Novel security models, metrics and security assessment networks
    Enoch, Simon Yusuf
    Lee, Jang Se
    Kim, Dong Seong
    [J]. COMPUTER NETWORKS, 2021, 189
  • [35] Towards Security Assurance Metrics for Service Systems Security
    Ouedraogo, Moussa
    [J]. EXPLORING SERVICES SCIENCE, 2012, 103 : 361 - 370
  • [36] Objective Quality Metrics in Correlation with Subjective Quality Metrics for Steganography
    Wazirali, Raniyah
    Slehat, Shaher
    Chaczko, Zenon
    Borowik, Grzegorz
    Carrion, Lucia
    [J]. 2015 ASIA-PACIFIC CONFERENCE ON COMPUTER-AIDED SYSTEM ENGINEERING - APCASE 2015, 2015, : 238 - 245
  • [37] Revisiting the Regression between Raw Outputs of Image Quality Metrics and Ground Truth Measurements
    Jung, Chanho
    Joo, Sanghyun
    Nam, Do-Won
    Kim, Wonjun
    [J]. IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2016, E99D (11): : 2778 - 2787
  • [38] Automotive Camera Quality Measurements based on Stability, Contrast and Intensity Metrics in Text Regions
    Youn, Sungwook
    Lee, Chulhee
    [J]. SATELLITE DATA COMPRESSION, COMMUNICATIONS, AND PROCESSING VIII, 2012, 8514
  • [39] IoT Metrics and Automation for Security Evaluation
    Setzler, Thomas
    Mountrouidou, Xenia
    [J]. 2021 IEEE 18TH ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC), 2021,
  • [40] Towards a Taxonomy for Information Security Metrics
    Savola, Reijo M.
    [J]. QOP'07: PROCEEDINGS OF THE 2007 ACM WORKSHOP ON QUALITY OF PROTECTION, 2007, : 28 - 30