首页> 外文会议>International conference on applied computing and information technology >Risk Assessment of Security Requirements of Banking Information Systems Based on Attack Patterns
【24h】

Risk Assessment of Security Requirements of Banking Information Systems Based on Attack Patterns

机译:基于攻击模式的银行信息系统安全需求风险评估

获取原文

摘要

Security risk assessment is an important process for the implementation of any information systems including those in the banking sector. When a bank initiates or implements an information system project, requirements engineers or business analysts in the project conduct an initial validation of system security requirements to check if they comply with banking security regulations before an audit takes place. This paper presents an initial risk assessment method to assist the project team in validating security requirements of a banking information system. Text similarity analysis is used to identify which security regulations are missing from the security requirements of the bank, and a quantitative risk index model is also proposed to determine the level of risk associated with the regulations missing from the requirements. The risk level is based on the harm any potential attacks can do to the information system if the missing regulations are not implemented. Using a case study of banking in Thailand, we apply the method to assess security requirements of Thai commercial banks against the IT Best Practices of the Bank of Thailand. We evaluate the performance of security compliance checking in terms of F-measure and accuracy, and validity of risk assessment in terms of correlation with security expert judgment.
机译:安全风险评估是实施包括银行业在内的任何信息系统的重要过程。当银行启动或实施信息系统项目时,项目中的需求工程师或业务分析人员将对系统安全需求进行初步验证,以在审核之前检查它们是否符合银行安全法规。本文提出了一种初始风险评估方法,以帮助项目团队验证银行信息系统的安全要求。文本相似性分析用于确定银行的安全需求中缺少哪些安全规则,并且还提出了定量风险指数模型,以确定与需求中缺失的规则相关的风险级别。风险级别基于如果未实施缺少的法规,则任何潜在的攻击都可能对信息系统造成的损害。通过对泰国银行业的案例研究,我们运用该方法根据泰国银行的IT最佳实践评估了泰国商业银行的安全要求。我们根据F度量和准确性评估安全合规性检查的性能,并根据与安全专家判断的相关性评估风险评估的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号