Security and Business Situational Awareness

被引:0
|
作者
Rieke, Roland [1 ,2 ]
Zhdanova, Maria [1 ]
Repp, Juergen [1 ]
机构
[1] Fraunhofer Inst SIT, Darmstadt, Germany
[2] Univ Marburg, Marburg, Germany
关键词
Predictive security analysis; Process behavior analysis; Security modeling and simulation; Security monitoring; Security strategy; Security information and event management; Governance and compliance; PERSPECTIVE; ENTERPRISE; FRAMEWORK; SYSTEMS;
D O I
10.1007/978-3-319-25360-2_9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
"Security needs to be aligned with business". Business situational awareness is the ability to continually monitor ongoing actions and events related to business operations and estimate the immediate and close-future impact of the new information. This ability is crucial for business continuity and should encompass all associated aspects. Considering the growing dependability of businesses on IT on the one hand, and ever increasing threats on the other, IT security aspects should get adequate attention in the awareness system. We present an approach to raise business situational awareness using an advanced method of predictive security analysis at runtime. It continually observes a system's event stream to find deviations from specified behavior and violations of security compliance rules. Operational models of the key processes are utilized to predict critical security states, evaluate possible countermeasures, and trigger corrective actions. A security information model maintains the security strategy and explains possible deviations from the originating goal. The approach is demonstrated on an industrial scenario from a European research project.
引用
收藏
页码:103 / 115
页数:13
相关论文
共 50 条
  • [1] Cyber Security Situational Awareness
    Tianfield, Huaglory
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON INTERNET OF THINGS (ITHINGS) AND IEEE GREEN COMPUTING AND COMMUNICATIONS (GREENCOM) AND IEEE CYBER, PHYSICAL AND SOCIAL COMPUTING (CPSCOM) AND IEEE SMART DATA (SMARTDATA), 2016, : 782 - 787
  • [2] Survey of Network Security Situational Awareness
    Yao, Jiayu
    Fan, Xiani
    Cao, Ning
    [J]. CYBERSPACE SAFETY AND SECURITY, PT I, 2020, 11982 : 34 - 44
  • [3] Situational Awareness Technology in Network Security
    Ye, Zheng-wang
    [J]. 2014 2ND INTERNATIONAL CONFERENCE ON SOCIAL SCIENCE AND HEALTH (ICSSH 2014), PT 4, 2014, 58 : 247 - 251
  • [4] Enabling situational awareness of business processes
    Zhao, Xiaohui
    Yongchareon, Sira
    Cho, Nam-Wook
    [J]. BUSINESS PROCESS MANAGEMENT JOURNAL, 2021, 27 (03) : 779 - 795
  • [5] Security Evaluation for Cyber Situational Awareness
    Kotenko, Igor
    Doynikova, Elena
    [J]. 2014 IEEE INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS, 2014 IEEE 6TH INTL SYMP ON CYBERSPACE SAFETY AND SECURITY, 2014 IEEE 11TH INTL CONF ON EMBEDDED SOFTWARE AND SYST (HPCC,CSS,ICESS), 2014, : 1197 - 1204
  • [6] An Extraction Method Of Situational Factors For Network Security Situational Awareness
    Wang, Huiqiang
    Liang, Ying
    Ye, Haizhi
    [J]. ICICSE: 2008 INTERNATIONAL CONFERENCE ON INTERNET COMPUTING IN SCIENCE AND ENGINEERING, PROCEEDINGS, 2008, : 317 - 320
  • [7] Architecture for the Cyber Security Situational Awareness System
    Kokkonen, Tero
    [J]. INTERNET OF THINGS, SMART SPACES, AND NEXT GENERATION NETWORKS AND SYSTEMS, NEW2AN 2016/USMART 2016, 2016, 9870 : 294 - 302
  • [8] A Study on the State of Practice in Security Situational Awareness
    Kanstren, Teemu
    Evesti, Antti
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY COMPANION (QRS-C 2016), 2016, : 69 - 76
  • [9] Cyber Security Situational Awareness among Parents
    Ahmad, Nazilah
    Mokhtar, Umi Asma
    Othman, Zulaiha Ali
    Abdullah, Siti Norul Huda Sheikh
    Fauzi, Wan Fariza Paizi
    Yeop, Yusri Hakim
    [J]. PROCEEDINGS OF THE 2018 CYBER RESILIENCE CONFERENCE (CRC), 2018,
  • [10] Blockchain Security Situational Awareness Method Based on
    Luo, Zhiyong
    Song, Weiwei
    Zhang, Wenbo
    Wang, Jianming
    Li, Jie
    [J]. JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2023, 45 (04) : 1374 - 1382