首页> 外文期刊>Technology Innovation Management Review >Quantitative Metrics and Risk Assessment: The Three Tenets Model of Cybersecurity
【24h】

Quantitative Metrics and Risk Assessment: The Three Tenets Model of Cybersecurity

机译:量化指标和风险评估:网络安全的三个原则模型

获取原文
           

摘要

Progress in operational cybersecurity has been difficult to demonstrate. In spite of the considerable research and development investments made for more than 30 years, many government, industrial, financial, and consumer information systems continue to be successfully attacked and exploited on a routine basis. One of the main reasons that progress has been so meagre is that most technical cybersecurity solutions that have been proposed to-date have been point solutions that fail to address operational tradeoffs, implementation costs, and consequent adversary adaptations across the full spectrum of vulnerabilities. Furthermore, sound prescriptive security principles previously established, such as the Orange Book, have been difficult to apply given current system complexity and acquisition approaches. To address these issues, the authors have developed threat-based descriptive methodologies to more completely identify system vulnerabilities, to quantify the effectiveness of possible protections against those vulnerabilities, and to evaluate operational consequences and tradeoffs of possible protections.
机译:运营网络安全方面的进展很难证明。尽管进行了30多年的大量研发投入,但许多政府,工业,金融和消费者信息系统仍在常规基础上继续受到成功的攻击和利用。进展如此之薄的主要原因之一是,迄今为止,已提出的大多数技术网络安全解决方案都是点解决方案,无法解决整个漏洞范围内的运营权衡,实施成本以及随之而来的对手适应问题。此外,鉴于当前的系统复杂性和获取方法,先前建立的健全的规范安全性原则(例如《橙皮书》)很难应用。为了解决这些问题,作者开发了基于威胁的描述性方法,以更完整地识别系统漏洞,量化针对这些漏洞的可能防护的有效性,并评估操作后果和可能防护的权衡。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号