首页> 外文期刊>Journal of Information Systems Applied Research >A Process for Assessing Voting System Risk Using Threat Trees
【24h】

A Process for Assessing Voting System Risk Using Threat Trees

机译:使用威胁树评估投票系统风险的过程

获取原文
       

摘要

Security continues to be a critical issue in the safe operation of electronic voting machines. Risk assessment is the process of determining if a particular voting system is at risk and what steps can be taken to mitigate the risk. We propose an iterative risk assessment process using threat trees. This process involves using a voting system risk taxonomy to categorize a threat, a schema to express logical hypothesis about a threat, generating a threat tree through functional decomposition, expressing threat instance semantics as nodal properties with metrics, validating the threat instance through independent representations, and finally pruning the tree for enhanced usability and understandability. This process provides guidance to an analyst in using threat trees to conduct risk assessment of electronic voting systems. Because this process is based on abstract and extendable structures, it facilitates the comparison and validation of independent risk evaluations. Prospective voting system risk assessment metrics are provided.
机译:安全性仍然是电子投票机安全运行中的关键问题。风险评估是确定特定投票系统是否存在风险以及可以采取哪些步骤来减轻风险的过程。我们提出了使用威胁树的迭代风险评估过程。该过程涉及使用表决系统风险分类法对威胁进行分类,表示威胁的逻辑假设的架构,通过功能分解生成威胁树,将威胁实例语义表示为带有度量的节点属性,通过独立表示来验证威胁实例,最后修剪树以增强可用性和可理解性。该过程为分析师提供了使用威胁树进行电子投票系统风险评估的指南。因为此过程基于抽象和可扩展的结构,所以它有助于独立风险评估的比较和验证。提供了预期的投票系统风险评估指标。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号