Threat scenario-based security risk analysis using use case modeling in information systems

被引:7
|
作者
Kim, Young-Gab [1 ]
Cha, Sungdeok [1 ]
机构
[1] Korea Univ, Coll Informat & Commun, Ctr Engn & Educ Dependable Software, Seoul 136701, South Korea
关键词
security risk analysis; qualitative risk analysis; scenario method; use case modeling; Broadband convergence Network (BcN);
D O I
10.1002/sec.321
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Successful Security Risk Analysis (SRA) enables us to develop a secure information management system and provides valuable analysis data for future risk estimation. One of the qualitative techniques for SRA is the scenario method. This provides a framework for our explorations that raises our awareness and appreciation of uncertainty. However, the existing scenario methods are too abstract to be applicable to some situations and have not been formalized in information systems (ISs) because they do not explicitly define artifacts or have any standard notation. Therefore, this paper proposes the improved scenario-based SRA approach, which can create SRA reports using threat scenario templates and manage security risk directly in ISs. Furthermore, in order to show how to apply the proposed method in a specific environment, especially in a Broadband convergence Network (BcN) environment, a case study is presented. Copyright (C) 2011 John Wiley & Sons, Ltd.
引用
收藏
页码:293 / 300
页数:8
相关论文
共 50 条
  • [1] Scenario-Based Modeling in Industrial Information Systems
    Machado, Ricardo J.
    Fernandes, Joao M.
    Barros, Joao P.
    Gomes, Luis
    [J]. DISTRIBUTED, PARALLEL AND BIOLOGICALLY INSPIRED SYSTEMS, 2010, 329 : 19 - +
  • [2] A Scenario-Based Information Security Risk Evaluation Method
    Ban, Xiaofang
    Tong, Xin
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2014, 8 (05): : 21 - 30
  • [3] Threat Scenario Dependency-Based Model of Information Security Risk Analysis
    Rahmad, Basuki
    Supangkat, Suhono H.
    Sembiring, Jaka
    Surendro, Kridanto
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2010, 10 (08): : 93 - 102
  • [4] Climate Change Effects on Transportation Infrastructure Scenario-Based Risk Analysis Using Geographic Information Systems
    Wu, Yao-Jan
    Hayat, Tanveer
    Clarens, Andres
    Smith, Brian L.
    [J]. TRANSPORTATION RESEARCH RECORD, 2013, (2375) : 71 - 81
  • [5] Scenario-based threat detection and attack analysis
    Hsiu, PC
    Kuo, CF
    Kuo, TW
    Juan, EYT
    [J]. 39TH ANNUAL 2005 INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY, PROCEEDINGS, 2005, : 279 - 282
  • [6] Scenario-Based Modeling for Electromagnetic Interference Analysis on Wireless Systems
    Wiklundh, Kia
    Stenumgaard, Peter
    Fors, Karina
    Linder, Sara
    Holm, Peter
    Junholm, Leif
    [J]. 2014 INTERNATIONAL SYMPOSIUM ON ELECTROMAGNETIC COMPATIBILITY (EMC EUROPE), 2014, : 1269 - 1274
  • [7] SCENARIOTOOLS - A tool suite for the scenario-based modeling and analysis of reactive systems
    Greenyer, Joel
    Gritzner, Daniel
    Gutjahr, Timo
    Koenig, Florian
    Glade, Nils
    Marron, Assaf
    Katz, Guy
    [J]. SCIENCE OF COMPUTER PROGRAMMING, 2017, 149 : 15 - 27
  • [8] Scenario-based Supply Chain Network risk modeling
    Klibi, Walid
    Martel, Alain
    [J]. EUROPEAN JOURNAL OF OPERATIONAL RESEARCH, 2012, 223 (03) : 644 - 658
  • [9] A scenario-based procedure for seismic risk analysis
    Kluegel, J.-U.
    Mualchin, L.
    Panza, G. F.
    [J]. ENGINEERING GEOLOGY, 2006, 88 (1-2) : 1 - 22
  • [10] Emerging technologies in civil security-A scenario-based analysis
    Bierwisch, Antje
    Kayser, Victoria
    Shala, Erduana
    [J]. TECHNOLOGICAL FORECASTING AND SOCIAL CHANGE, 2015, 101 : 226 - 237