首页> 外文会议>2013 IEEE 2nd Network Science Workshop >A meta-network approach for analysing the information system access vulnerabilities in organizations
【24h】

A meta-network approach for analysing the information system access vulnerabilities in organizations

机译:一种元网络方法,用于分析组织中的信息系统访问漏洞

获取原文
获取原文并翻译 | 示例

摘要

Access control is an important aspect of information systems security. The primary concern in access vulnerability research has been the development of secure technologies for subjects to gain access to objects. Very little emphasis is placed on access vulnerabilities that occur due to socio-technical factors. However, a holistic access vulnerability analysis that considers a range of socio-technical factors is required for the implementation of access control principles such as the need-to-know, separation of duties and dual control. This paper describes a research aimed at investigating a meta-network modeling approach to analyze access vulnerabilities that could be mitigated by the application of three access control principles mentioned above. In this research data collected from an organization is instantiated as a meta-network and analyzed using three different metrics. The results suggest that a meta-network model and the chosen metrics are suitable for a holistic analysis of socio-technical information system access vulnerabilities.
机译:访问控制是信息系统安全的重要方面。访问漏洞研究的主要关注点是开发安全技术,以使主体能够访问对象。很少强调由于社会技术因素而发生的访问漏洞。但是,为了实现访问控制原则(例如,需要了解,职责分离和双重控制),需要考虑一系列社会技术因素的整体访问漏洞分析。本文介绍了一项旨在研究元网络建模方法的研究,以分析可以通过应用上述三种访问控制原理来缓解的访问漏洞。在这项研究中,将从组织收集的数据实例化为元网络,并使用三种不同的指标进行分析。结果表明,元网络模型和选择的度量标准适合对社会技术信息系统访问漏洞进行整体分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号