A decision model based security risk management approach

被引:0
|
作者
Bhattacharya, Somak [1 ]
Ghosh, S. K. [2 ,3 ]
机构
[1] Indian Inst Technol, Informat Technol, Kharagpur, W Bengal, India
[2] Indian Inst Technol, Sch Informat Technol, Kharagpur, W Bengal, India
[3] Govt India, ISRO, Dept Space, Bangalore, Karnataka, India
关键词
attack graph; exploit; risk management; vulnerability; attack path;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With increasing availability of computing system the enterprises are becoming increasing dependent on IT infrastructure and thus becoming vulnerable to threats. To assess the security of enterprise network, one must first understand how vulnerabilities can be combined for an attack Such an understanding becomes possible with recent advances in modeling the composition of vulnerabilities as attack graphs. An attack graph is a general formalism used to model security vulnerabilities of a system and all possible sequences of exploits which an intruder can use to achieve a specific goal. However, as the size and computational complexity of attack graphs greatly exceeds human ability to visualize, understand and analyze, a model is required to identify high probable paths of attack graphs that a potential attacker may follow. One method for handling attack graph complexity and scalability is to differentiate between likely and unlikely attack paths using threat modeling. Threat modeling is used during risk assessment to describe likely and unlikely adversary behavior, and so can be used for the same purpose during attack graph analysis and attack path identification out of it. The proposed approach uses a decision theoretic model to identify the most probable attack path using threat modeling.
引用
收藏
页码:1194 / 1199
页数:6
相关论文
共 50 条
  • [1] Towards a decision model based on trust and security risk management
    Alcalde, Baptiste
    Dubois, Eric
    Mauw, Sjouke
    Mayer, Nicolas
    Radomirović, Saša
    [J]. Conferences in Research and Practice in Information Technology Series, 2009, 98 : 61 - 69
  • [2] Security risk factors: ANP model for risk management decision making
    Brozova, Helena
    Rydval, Jan
    Sup, Libor
    Sadok, Moufida
    Bednar, Peter
    [J]. 33RD INTERNATIONAL CONFERENCE MATHEMATICAL METHODS IN ECONOMICS (MME 2015), 2015, : 74 - 79
  • [3] Outsource or not? An AHP Based Decision Model for Information Security Management
    Jelovcan, Luka
    Mihelic, Anze
    Prislan, Kaja
    [J]. ORGANIZACIJA, 2022, 55 (02) : 142 - 159
  • [4] Model based risk management of security critical systems
    Djordjevic, I
    Gan, C
    Scharf, E
    Mondragon, R
    Gran, BA
    Kristiansen, M
    Dimitrakos, T
    Stolen, K
    Opperud, TA
    [J]. RISK ANALYSIS III, 2002, 5 : 253 - 264
  • [5] Bayesian Decision Network-Based Security Risk Management Framework
    Masoud Khosravi-Farmad
    Abbas Ghaemi-Bafghi
    [J]. Journal of Network and Systems Management, 2020, 28 : 1794 - 1819
  • [6] Bayesian Decision Network-Based Security Risk Management Framework
    Khosravi-Farmad, Masoud
    Ghaemi-Bafghi, Abbas
    [J]. JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2020, 28 (04) : 1794 - 1819
  • [7] Ontology-based Decision Support for Information Security Risk Management
    Ekelhart, Andreas
    Fenz, Stefan
    Neubauer, Thomas
    [J]. 2009 FOURTH INTERNATIONAL CONFERENCE ON SYSTEMS (ICONS), 2009, : 80 - +
  • [8] Integrating model-based security risk management into eBusiness systems development - The CORAS approach
    Dimitrakos, T
    Ritchie, B
    Raptis, D
    Aagedal, JO
    den Braber, F
    Stolen, K
    Houmb, SH
    [J]. TOWARDS THE KNOWLEDGE SOCIETY: E-COMMERCE, E-BUSINESS, AND E-GOVERNMENT, 2003, 105 : 159 - 175
  • [9] An iterative mathematical decision model for cloud migration: A cost and security risk approach
    Shirvani, Mirsaeid Hosseini
    Rahmani, Amir Masoud
    Sahafi, Amir
    [J]. SOFTWARE-PRACTICE & EXPERIENCE, 2018, 48 (03): : 449 - 485
  • [10] Approach to a Bayesian decision model for cost-benefit analysis in security risk
    Lichte, D.
    Wolf, K. -D.
    [J]. SAFETY AND RELIABILITY - SAFE SOCIETIES IN A CHANGING WORLD, 2018, : 1819 - 1826