首页> 外文会议>Companion of the IEEE International Conference on Software Quality, Reliability, and Security >Trial Development of a Cyber Risk Visualization System with Function of k-Anonymity and Compatibility with Other Organizations
【24h】

Trial Development of a Cyber Risk Visualization System with Function of k-Anonymity and Compatibility with Other Organizations

机译:试验开发网络风险可视化系统,具有k-匿名功能和与其他组织的兼容性

获取原文

摘要

This paper deals with the trial development of a new cyber risk visualization system. Although numerous organizations have implemented a wide variety of information technology (IT) systems in recent years, the number of cybersecurity incidents demanding rapid and efficient responses continues to increase. Furthermore, while it is desirable for organizations to set appropriate target levels when addressing such risks, the process is difficult because managers are seldom information security specialists. In such situations, management typically sets goals regarding information security, communicates risk factors with the information department, and then provides decision support for concrete measures. However, the fact that they are not security experts often makes it difficult to implement these measures. As a partial countermeasure to such cases, we believe that an approach by which an organization can gain an understanding of similar situations in other organizations, understand and adjust the methods by which they approach related issues, and then adapt those methods to their own use can be effective. However, a primary concern regarding information sharing between organizations is that while one organization may desire to know the status of other organizations, they do not want necessarily want to share similar information related to their own organizations. As a result, active efforts to facilitate such sharing have seen little progress. In this paper, we report on the development of a system that visualizes cyber-risks related to a particular organization, shows similar results for other organizations in the form of average values within a range that allows k-anonymity to be maintained, and then makes comparisons among those results. This makes it difficult for other participating organizations to gain a specific understanding of conditions within a specific organization. We then developed a prototype system using LimeSurvey, which is an easily modifiable open source web application, in order to make our proposed system easy to customize and use. Our experimental results show that this prototype enables comparisons to be made regarding situations among various participating organizations in the same industries while maintaining the anonymity of each individual organization.
机译:本文涉及新网络风险可视化系统的试验开发。虽然近年来,众多组织实施了各种信息技术(IT)系统,但节目迅速高效响应的网络安全事件的数量仍在继续增加。此外,虽然组织在解决此类风险时可用于设置适当的目标级别,但该过程很难,因为管理人员是很少的信息安全专家。在这种情况下,管理通常会设定有关信息安全的目标,使风险因素与信息部门进行传达,然后为具体措施提供决策支持。然而,他们不是安全专家的事实往往使得难以实施这些措施。作为这种情况的部分对策,我们相信组织可以在其他组织中获得类似情况的方法,了解和调整他们接近相关问题的方法,然后将这些方法适应自己的使用有效。然而,关于组织之间的信息共享一个主要问题是,当一个组织可能希望了解其他组织的地位,他们不想一定要分享有关他们自己的组织类似的信息。因此,有助于这种共享的积极努力几乎没有进展。在本文中,我们报告了一个可视化与特定组织相关的网络风险的系统的开发,显示了与允许维护k-匿名性的范围内的平均值形式的其他组织的类似结果,然后制作这些结果的比较。这使得其他参与组织难以确定对特定组织内的条件的具体了解。然后,我们使用Limesurvey开发了一个原型系统,这是一个易于修改的开源Web应用程序,以便我们提出的系统易于自定义和使用。我们的实验结果表明,该原型能够在同一行业的各种参与组织的情况下进行比较,同时保持每个组织的匿名性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号