首页> 外文会议>Risk Assessment and Risk-Driven Quality Assurance >Quantitative Information Security Risk Estimation Using Probabilistic Attack Graphs
【24h】

Quantitative Information Security Risk Estimation Using Probabilistic Attack Graphs

机译:使用概率攻击图的定量信息安全风险估计

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

This paper proposes an approach, called pwnPr3d, for quantitatively estimating information security risk in ICT systems. Unlike many other risk analysis approaches that rely heavily on manual work and security expertise, this approach comes with built-in security risk analysis capabilities. pwnPr3d combines a network architecture modeling language and a probabilistic inference engine to automatically generate an attack graph, making it possible to identify threats along with the likelihood of these threats exploiting a vulnerability. After defining the value of information assets to their organization with regards to confidentiality, integrity and availability breaches, pwnPr3d allows users to automatically quantify information security risk over time, depending on the possible progression of the attacker. As a result, pwnPr3d provides stakeholders in organizations with a holistic approach that both allows high-level overview and technical details.
机译:本文提出了一种称为pwnPr3d的方法,用于定量估计ICT系统中的信息安全风险。与许多其他严重依赖手动工作和安全专业知识的风险分析方法不同,此方法具有内置的安全风险分析功能。 pwnPr3d结合了网络体系结构建模语言和概率推理引擎来自动生成攻击图,从而可以识别威胁以及这些威胁利用漏洞的可能性。在针对机密性,完整性和可用性违规定义了信息资产对其组织的价值之后,pwnPr3d允许用户随时间推移自动量化信息安全风险,具体取决于攻击者的可能进程。结果,pwnPr3d为组织中的利益相关者提供了一种全面的方法,该方法可以同时提供高级概述和技术细节。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号