首页> 外文会议>International topical meeting on probabilistic safety assessment and analysis >VALIDATING A CYBER SECURITY RISK-INFORMED DECISION MODEL: WISHES AND REALITY
【24h】

VALIDATING A CYBER SECURITY RISK-INFORMED DECISION MODEL: WISHES AND REALITY

机译:验证网络安全风险明智的决策模型:愿望和现实

获取原文

摘要

Cyber security is a field in which it is especially difficult to obtain experts' insights and gather data. This paper discusses the challenges of development and validation of a cyber security risk-informed decision model. Model validation is necessary to ensure that a model reflects the system being represented and is crucial for users of the model to trust it. However, sound and convincing validation is difficult to achieve. Reasons include unavailability of experts to give their insights, or unavailability of data. Validation is even more challenging in the field of cyber security, in which there is a mistrust regarding anyone who is attempting to capture experts' insights or obtaining data. In this paper, we highlight the challenges of model validation and present our approach to achieve validation, although imperfect, of a cyber security decision model. This validation is based on three years of collaboration with the Director of Security at the University of Maryland (UMD), on interviews and surveys of experts, and on security data collected at UMD.
机译:网络安全是一个领域,其中特别难以获得专家的见解和收集数据。本文讨论了网络安全风险明智决策模型的开发和验证的挑战。模型验证是必要的,以确保模型反映了所代表的系统,并且对模型的用户来说至关重要以信任它。但是,难以实现声音和令人信服的验证。原因包括专家的不可用,以提供他们的见解或数据的不可用。验证在网络安全领域更具挑战性,在那时有人对任何试图捕获专家见解或获取数据的人都有信任。在本文中,我们突出了模型验证的挑战,并呈现了我们实现验证的方法,尽管网络安全决策模型不完美。该验证是基于三年与马里兰州大学(UMD)的安全主管合作,参加专家的访谈和调查以及在UMD收集的安全数据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号