首页> 外文会议>International workshop on information security application >A Study on Analyzing Risk Scenarios About Vulnerabilities of Security Monitoring System: Focused on Information Leakage by Insider
【24h】

A Study on Analyzing Risk Scenarios About Vulnerabilities of Security Monitoring System: Focused on Information Leakage by Insider

机译:安全监控系统漏洞风险情景分析研究:以内部人信息泄漏为中心

获取原文

摘要

Information leakage by insider results in financial losses and ethical issues, thus affects business sustainability as well as corporate reputation. In Korea, information leakage by insiders occupies about 80% of the security incidents. Most companies are establishing preventive and prohibited security policies. Nevertheless, security incidents are unceasing. Such restrictive security policies inhibit work efficiency or make employees recognize security negatively. Due to these problems, the rapid detection capability of leakage signs is required. To detect the signs of information leakage, security monitoring is an essential activity. This study is an exploratory case study that analyzed the current state of security monitoring operated by three companies in Korea and provides some risk scenarios about information leakage. For the case analysis, this study collected each company's security policy, systems linked with security monitoring system, and system log used. As a result, this study identified vulnerabilities that were difficult to be detected with the current security monitoring system, and drew 4 risk scenarios that were likely to occur in the future. The results of this study will be useful for the companies that arc planning to establish effective security monitoring system.
机译:内部人员的信息泄漏会导致财务损失和道德问题,从而影响业务的可持续性以及企业声誉。在韩国,内部人员泄漏的信息约占安全事件的80%。大多数公司都在建立预防和禁止的安全策略。尽管如此,安全事件仍在持续。这种限制性的安全策略会降低工作效率,或使员工对安全产生负面认识。由于这些问题,需要快速检测泄漏迹象。为了检测信息泄漏的迹象,安全监视是一项必不可少的活动。这项研究是一个探索性案例研究,分析了韩国三家公司运营的安全监视的现状,并提供了一些有关信息泄漏的风险方案。对于案例分析,本研究收集了每个公司的安全策略,与安全监视系统链接的系统以及所使用的系统日志。结果,本研究确定了使用当前的安全监视系统很难检测到的漏洞,并绘制了4种将来可能发生的风险方案。这项研究的结果对计划建立有效的安全监控系统的公司很有用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号