Design and Development of a Technique for the Automation of the Risk Analysis Process in IT Security

被引:11
|
作者
Granata, Daniele [1 ]
Rak, Massimiliano [1 ]
机构
[1] Univ Campania Luigi Vanvitelli, Dept Engn, Aversa, Italy
关键词
Threat Modeling; Risk Analysis; Threat Agent; Protocols;
D O I
10.5220/0010455200870098
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Cloud service architectures are very heterogeneous and commonly relies on components managed by third parties. As a consequence, the security verification process of these architectures is a complex and costly process. Moreover, development of application that runs in cloud should take into account the agile software design and development methodologies and a really short time-to market, which are often incompatible with deep security testing. This article aims at addressing such issues proposing a technique, compatible with Security-By-Design methodologies, that automates the threat modeling and risk evaluation of a system, reducing the costs and requiring a limited set of security skills. Through the proposed approach, the software system is analysed identifying the threats that affects the system technical assets, ranking the level of risk associated to each threat and suggesting a set of countermeasures in standard terms; the process requires a minimal user interaction. The proposed technique, was implemented through a dedicated tool and, correctly integrated in development processes, can significantly reduce the need of costly security experts and shorten the time needed to execute a full system security assessment. In order to validate the technique, we compared our results with approaches available in literature and existing tools.
引用
收藏
页码:87 / 98
页数:12
相关论文
共 50 条
  • [1] Risk Analysis Automation Process in IT Security for Cloud Applications
    Granata, Daniele
    Rak, Massimiliano
    Salzillo, Giovanni
    [J]. CLOUD COMPUTING AND SERVICES SCIENCE, CLOSER 2021, 2022, 1607 : 47 - 68
  • [2] AN ANALYSIS OF EFFECTS OF DESIGN AUTOMATION ON DEVELOPMENT OF ENGINEERING PROCESS
    HILL, LS
    [J]. AACE BULLETIN, 1969, 11 (01): : 15 - &
  • [3] Security risk analysis for smart grid automation
    Sierla, Seppo
    Hurkala, Marcin
    Charitoudi, Konstantinia
    Yang, Chen-Wei
    Vyatkin, Valeriy
    [J]. 2014 IEEE 23RD INTERNATIONAL SYMPOSIUM ON INDUSTRIAL ELECTRONICS (ISIE), 2014, : 1737 - 1744
  • [4] System Design and Development for Robotic Process Automation
    Ma, Yi-Wei
    Lin, Dan-Ping
    Chen, Shiang-Jiun
    Chu, Hsiu-Yuan
    Chen, Jiann-Liang
    [J]. 4TH IEEE INTERNATIONAL CONFERENCE ON SMART CLOUD (SMARTCLOUD 2019) / 3RD INTERNATIONAL SYMPOSIUM ON REINFORCEMENT LEARNING (ISRL 2019), 2019, : 187 - 189
  • [5] Integrating security decisions by design into the engineering of process plants Introducing the Automation Security by Design Decisions concept
    Fluchs, S.
    Tastan, E.
    Drath, R.
    Mertens, M.
    Ritter, J.
    Horch, A.
    Fay, A.
    [J]. VDI Berichte, 2022, 2022 (2399): : 115 - 132
  • [6] IT Security in Automation - Threat Analysis and the Development of Protection Strategies
    Schwibach, Martin
    Sieber, Peter
    [J]. ATP EDITION, 2014, (12): : 50 - 63
  • [7] Network Security Analysis SCADA System Automation on Industrial Process
    Hilal, Hamzah
    Nangim, Anas
    [J]. 2017 INTERNATIONAL CONFERENCE ON BROADBAND COMMUNICATION, WIRELESS SENSORS AND POWERING (BCWSP), 2017, : 76 - 81
  • [8] Process automation engineers in pat strategy development and design
    Sommer, Scott W.
    [J]. CHIMICA OGGI-CHEMISTRY TODAY, 2009, 27 (02): : III - vi
  • [9] Security in Process Automation - Trends and Developments from the Focus of the Apron Development
    Palmin, A.
    Runde, S.
    Kobes, P.
    [J]. AUTOMATION 2012, 2012, 2171 : 177 - 181
  • [10] Development of software tools for automation and acceleration of the engineering design process
    Harrington, BW
    [J]. 1998 IEEE AEROSPACE CONFERENCE PROCEEDINGS, VOL 4, 1998, : 265 - 275