Model based risk management of security critical systems

被引:0
|
作者
Djordjevic, I [1 ]
Gan, C [1 ]
Scharf, E [1 ]
Mondragon, R [1 ]
Gran, BA [1 ]
Kristiansen, M [1 ]
Dimitrakos, T [1 ]
Stolen, K [1 ]
Opperud, TA [1 ]
机构
[1] Univ London Queen Mary Coll, Dept Elect Engn, London E1 4NS, England
来源
RISK ANALYSIS III | 2002年 / 5卷
关键词
D O I
暂无
中图分类号
X [环境科学、安全科学];
学科分类号
08 ; 0830 ;
摘要
This paper describes a novel framework for a risk management process involving a model-based approach, developed as the main objective of CORAS (IST-2000 25031). The main motivation for this approach is to achieve an improved methodology for precise, unambiguous, and efficient risk analysis of security critical systems. There are several benefits from a model-based approach. Firstly, the description of the target system, its context and all security relevant features required for risk analysis, can be improved by applying state-of-the-art modelling technology. Secondly, it provides a rich set of graphical descriptions that address properties of the target system as well as their context (including the behaviour of humans), which improves communication and interaction between stakeholders involved in a risk analysis and also facilitates the formalization of threats and more precise documentation of risk analysis results and the assumptions. Finally, tighter integration of risk management in the system development process may considerably reduce the development costs. In this paper we place the emphasis on the proposed guidelines and recommendations for model-based risk management, which will be evaluated through trials in the e-commerce and telemedicine areas. Since CORAS is an ongoing project, the research described here is work in progress.
引用
收藏
页码:253 / 264
页数:12
相关论文
共 50 条
  • [21] A Data-driven Assessment Model for Information Systems Security Risk Management
    Feng, Nan
    Yu, Xue
    [J]. JOURNAL OF COMPUTERS, 2012, 7 (12) : 3103 - 3109
  • [22] Critical Infrastructure Cyber-Security Risk Management
    Spyridopoulos, Theodoros
    Maraslis, Konstantinos
    Tryfonas, Theo
    Oikonomou, George
    [J]. TERRORISTS' USE OF THE INTERNET: ASSESSMENT AND RESPONSE, 2017, 136 : 59 - 76
  • [23] Risk management of complex critical systems
    Koubatis, Andrew
    Schoenberger, Jorge Yerena
    [J]. INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURES, 2005, 1 (2-3) : 195 - 215
  • [24] A Model Based Approach to System of Systems Risk Management
    Kinder, Andrew
    Henshaw, Michael
    Siemieniuch, Carys
    [J]. 2015 10th System of Systems Engineering Conference (SoSE), 2015, : 122 - 127
  • [25] A Security Model for Internet-Based Digital Asset Management Systems
    Chatzigiannakis, I.
    Liagkou, V.
    Salouros, D.
    Spirakis, P.
    [J]. SOFTWARE ARCHITECTURE, 2008, 5292 : 326 - +
  • [26] A RISK MANAGEMENT MODEL BASED ON USER PERCEPTION FOR INFORMATION SYSTEMS SECURITY AT UNIVERSIDAD NACIONAL DEL ALTIPLANO PUNO
    Condori Alejo, Henry Ivan
    [J]. REVISTA INVESTIGACIONES ALTOANDINAS-JOURNAL OF HIGH ANDEAN RESEARCH, 2013, 15 (01): : 23 - 34
  • [27] Information security risk assessment model for risk management
    Wawrzyniak, Dariusz
    [J]. TRUST, PRIVACY, AND SECURITY IN DIGITAL BUSINESS, PROCEEDINGS, 2006, 4083 : 21 - 30
  • [28] Model-based risk assessment for cyber physical systems security
    Tantawy, Ashraf
    Abdelwahed, Sherif
    Erradi, Abdelkarim
    Shaban, Khaled
    [J]. COMPUTERS & SECURITY, 2020, 96
  • [29] Model-Based Security Risk Analysis for Networked Embedded Systems
    Vasilevskaya, Maria
    Nadjm-Tehrani, Simin
    [J]. CRITICAL INFORMATION INFRASTRUCTURES SECURITY (CRITIS 2014), 2016, 8985 : 381 - 386
  • [30] SMART: security model adversarial risk-based tool for systems security design evaluation
    Wortman, Paul A.
    Chandy, John A.
    [J]. JOURNAL OF CYBERSECURITY, 2020, 6 (01): : 1 - 8