Model-based risk assessment to improve enterprise security

被引:39
|
作者
Aagedal, JO [1 ]
den Braber, F [1 ]
Dimitrakos, T [1 ]
Gran, BA [1 ]
Raptis, D [1 ]
Stolen, K [1 ]
机构
[1] SINTEF, Telecom & Informat, N-0314 Oslo, Norway
关键词
D O I
10.1109/EDOC.2002.1137696
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The main objective of the CORAS project is to provide methods and tools for precise, unambiguous, and efficient risk assessment of security critical systems. To this end, we advocate a model-based approach to risk assessment, and this paper attempts to define the required models for this. Whereas traditional risk assessment is performed without any formal description of the target of evaluation or results of the risk assessment, CORAS aims to provide a well defined set of models well suited to (1) describe the target of assessment at the right level of abstraction, (2) as a medium for communication between different groups of stakeholders involved in a risk assessment, and (3) to document risk assessment results and the assumptions on which these results depend. We propose here models for each step in a risk assessment process and report results of use.
引用
收藏
页码:51 / 62
页数:12
相关论文
共 50 条
  • [1] A Model-Based Approach for Aviation Cyber Security Risk Assessment
    Kiesling, Tobias
    Niederl, Josef
    Ziegler, Juergen
    Krempel, Matias
    [J]. PROCEEDINGS OF 2016 11TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, (ARES 2016), 2016, : 517 - 525
  • [2] Model-based risk assessment for cyber physical systems security
    Tantawy, Ashraf
    Abdelwahed, Sherif
    Erradi, Abdelkarim
    Shaban, Khaled
    [J]. COMPUTERS & SECURITY, 2020, 96
  • [3] A risk assessment model for enterprise network security
    Yang, Fu-Hong
    Chi, Chi-Hung
    Liu, Lin
    [J]. AUTONOMIC AND TRUSTED COMPUTING, PROCEEDINGS, 2006, 4158 : 293 - 301
  • [4] Model-Based Cyber Security at the Enterprise and Systems Level
    Brooks, Mitchell
    Hause, Matthew
    [J]. INCOSE International Symposium, 2023, 33 (01) : 649 - 665
  • [5] An approach for model-based risk assessment
    Gran, BA
    Fredriksen, R
    Thunem, APJ
    [J]. COMPUTER SAFETY, RELIABILITY, AND SECURITY, PROCEEDINGS, 2004, 3219 : 311 - 324
  • [6] Model-based risk assessment evaluation
    Germanos, Vasileios
    Zeng, Wen
    [J]. SECURITY AND PRIVACY, 2022, 5 (05)
  • [7] Network Security Risk Assessment Based on Enterprise Environment Characteristics
    Yang, Yunxue
    Yang, Zhenqi
    Yang, Qin
    Ji, Guohua
    Xue, Shengjun
    [J]. International Journal of Network Security, 2022, 24 (01) : 156 - 165
  • [8] Towards Model-Based Security Assessment of Cloud Applications
    Casola, Valentina
    De Benedictis, Alessandra
    Nardone, Roberto
    [J]. GREEN, PERVASIVE, AND CLOUD COMPUTING (GPC 2017), 2017, 10232 : 773 - 785
  • [9] Study on Model-Based Security Assessment of Information Systems
    Li, Xiangdong
    Han, Xinchao
    Zheng, Qiusheng
    [J]. COMPUTING AND INTELLIGENT SYSTEMS, PT III, 2011, 233 : 401 - 406
  • [10] Study on Model-based Security Assessment of Information Systems
    Li, Xiangdong
    Han, Xinchao
    Zheng, Qiusheng
    [J]. 2010 SECOND INTERNATIONAL CONFERENCE ON E-LEARNING, E-BUSINESS, ENTERPRISE INFORMATION SYSTEMS, AND E-GOVERNMENT (EEEE 2010), VOL I, 2010, : 289 - 292