首页> 外文会议>IEEE International Conference on Cloud Computing Technology and Science >Defining #x0022;The Weakest Link#x0022; Comparative Security in Complex Systems of Systems
【24h】

Defining #x0022;The Weakest Link#x0022; Comparative Security in Complex Systems of Systems

机译:定义系统复杂系统中的“最薄弱的链接”比较安全

获取原文

摘要

Cloud architectures are complex socio-technical systems of systems, consisting not only of technological components and their connections, but also of physical premises and employees. When analysing security of such systems and considering countermeasures, the notion of "weakest link" often appears. Humans are then typically said to be the "weakest link" when it comes to security, but no proof is provided for this statement. One reason for this is the fact that there are no unified metrics of security that would apply to physical, digital and social components of complex systems alike. How does one compare the security of a room against the security of a piece of data, and how does social engineering an employee compare to exploiting a server vulnerability? Are we really comparing apples and oranges here, or would it be possible to present a comparative metric that would apply across the different domains? This paper explores the possibility of such a metric for complex systems, and proposes one in terms of the risk induced by an entity in the system. This also provides a foundation for the notion of "weakest link", in terms of the entity (set of entities) with the highest induced risk.
机译:云架构是复杂的系统社会技术系统,不仅包括技术部件及其联系,还包括物理处所和员工。在分析这种系统的安全性并考虑对策时,通常会出现“最弱的链接”的概念。然后,人类通常被称为安全性时的“最薄弱的联系”,但没有为此陈述提供证据。这是一个原因是,没有统一的安全性,适用于复杂系统的物理,数字和社会组件。如何将房间的安全性与一段数据的安全性进行比较,以及社会工程如何与利用服务器漏洞进行比较?我们是否真的在这里比较苹果和橘子,或者是否有可能呈现将在不同域中应用的比较度量?本文探讨了复杂系统的这种度量的可能性,并在系统中的实体引起的风险方面提出一个。这也为“最弱势环节”的概念提供了最高诱导风险的实体(实体集)的概念。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号