The information systems' security level assessment model based on an ontology and evidential reasoning approach

被引:18
|
作者
Solic, Kresimir [1 ,3 ]
Ocevcic, Hrvoje [2 ,3 ]
Golub, Marin [4 ]
机构
[1] Univ Osijek, Fac Med, HR-31000 Osijek, Croatia
[2] Hypoalpe Adria Bank Dd, Zagreb 10000, Croatia
[3] Univ Osijek, Fac Elect Engn, HR-31000 Osijek, Croatia
[4] Univ Zagreb, Fac Elect Engn & Comp, HR-10000 Zagreb, Croatia
关键词
Information security model; Information security; Risk assessment; Security control selection; Security management; OWL; Ontology; Evidential reasoning; DECISION-MAKING;
D O I
10.1016/j.cose.2015.08.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the area of information technology an amount of security issues persists through time. Ongoing activities on security solutions aim to integrate existing security guidelines, best practices, security standards and existing solutions, but they often lack a knowledge base or do not involve all security issues, particularly human influence. In this paper, we presented a model that can be the basis for a novel information systems security evaluation solution. This solution should be able to cover a wide range of all possible information security issues. Our model is based on an OWL ontology for knowledge base, uses an enhanced Evidential Reasoning algorithm for mathematical calculations and possesses a simple reflex intelligent agent's algorithm as a decision supporting element. Properties for this model supervene from properties of its constructing elements. Knowledge base being built on OWL ontology is a major element of the model. It can provide high flexibility and applicability to different information systems and business organizations; upgradeability to be up to date regarding current security issues and new threats; and high versatility, taking into evaluation all possible aspects regarding security issues, e.g., network security, software and hardware issues, human influence, security policies and disaster recovery plans. Enhanced Evidential Reasoning algorithm is based on the Dumpster-Shafer theory and is well suited for calculations with expert's subjective judgements combining qualitative with quantitative evaluation grades. We designed an algorithm for back coupling based on a simple reflex intelligent agent for results presentation and decision support. In our work, we explained how to connect and use each of the model's constructive elements to obtain information security evaluation results. In addition, we conducted a case study with the proposed model on a small business organization. To test our model, we also used the standard qualitative risk assessment method on the same business organization in order to compare both qualitative results. Preliminary testing results have shown that the presented model could achieve its goal if it would be developed into an integrated software tool with a well-defined and up-to-date ontological knowledge base. (C) 2015 Elsevier Ltd. All rights reserved.
引用
收藏
页码:100 / 112
页数:13
相关论文
共 50 条
  • [1] Assessment of information security levels in power communication systems using evidential reasoning
    Nordstroem, Lars
    [J]. IEEE TRANSACTIONS ON POWER DELIVERY, 2008, 23 (03) : 1384 - 1391
  • [2] Combat Capability Assessment Approach of Strategic Missile Systems based on Evidential Reasoning
    Luo, Ji-Li
    Li, Meng-Jun
    Jiang, Jiang
    You, Han-Lin
    Li, Yin-Ye
    Chen, Fang-Zhou
    [J]. 2015 2ND INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND CONTROL ENGINEERING ICISCE 2015, 2015, : 667 - 671
  • [3] An ontology-based approach to information systems security management
    Tsoumas, B
    Dritsas, S
    Gritzalis, D
    [J]. COMPUTER NETWORK SECURITY, PROCEEDINGS, 2005, 3685 : 151 - 164
  • [4] An Ontology Based Approach to Information Security
    Pereira, Teresa
    Santos, Henrique
    [J]. METADATA AND SEMANTIC RESEARCH, PROCEEDINGS, 2009, 46 : 183 - 192
  • [5] Fault prediction model based on evidential reasoning approach
    XiaoSheng Si
    ChangHua Hu
    ZhiJie Zhou
    [J]. Science China Information Sciences, 2010, 53 : 2032 - 2046
  • [6] Fault prediction model based on evidential reasoning approach
    Si XiaoSheng
    Hu ChangHua
    Zhou ZhiJie
    [J]. SCIENCE CHINA-INFORMATION SCIENCES, 2010, 53 (10) : 2032 - 2046
  • [7] Fault prediction model based on evidential reasoning approach
    SI XiaoSheng 1
    2 Department of Automation
    [J]. Science China(Information Sciences), 2010, 53 (10) : 2032 - 2046
  • [8] An Ontology-Based Security Risk Management Model for Information Systems
    Arogundade, Oluwasefunmi T.
    Abayomi-Alli, Adebayo
    Misra, Sanjay
    [J]. ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2020, 45 (08) : 6183 - 6198
  • [9] An Ontology-Based Security Risk Management Model for Information Systems
    Oluwasefunmi T. Arogundade
    Adebayo Abayomi-Alli
    Sanjay Misra
    [J]. Arabian Journal for Science and Engineering, 2020, 45 : 6183 - 6198
  • [10] Use of Fuzzy Evidential Reasoning in Maritime Security Assessment
    Yang, Z. L.
    Wang, J.
    Bonsall, S.
    Fang, Q. G.
    [J]. RISK ANALYSIS, 2009, 29 (01) : 95 - 120