首页> 外文期刊>Journal of network and systems management >A Formal Methodology for Detecting Managerial Vulnerabilities and Threats in an Enterprise Information System
【24h】

A Formal Methodology for Detecting Managerial Vulnerabilities and Threats in an Enterprise Information System

机译:用于检测企业信息系统中管理漏洞和威胁的形式化方法

获取原文
获取原文并翻译 | 示例
       

摘要

From information security point of view, an enterprise is considered as a collection of assets and their interrelationships. These interrelationships may be built into the enterprise information infrastructure, as in the case of connection of hardware elements in network architecture, or in the installation of software or in the information assets. As a result, access to one element may enable access to another if they are connected. An enterprise may specify conditions on the access of certain assets in certain mode (read, write etc.) as policies. The interconnection of assets, along with specified policies, may lead to managerial vulnerabilities in the enterprise information system. These vulnerabilities, if exploited by threats, may cause disruption to the normal functioning of information systems. This paper presents a formal methodology for detection of managerial vulnerabilities of, and threats to, enterprise information systems in linear time.
机译:从信息安全的角度来看,企业被视为资产及其相互关系的集合。这些相互关系可以内置在企业信息基础结构中,例如在网络体系结构中或软件安装或信息资产中连接硬件元素的情况下。结果,如果连接了一个元素,则可以访问另一个元素。企业可以指定以某种方式(读,写等)访问某些资产的条件作为策略。资产的互连以及指定的策略可能导致企业信息系统中的管理漏洞。如果被威胁利用,这些漏洞可能会导致信息系统正常运行的中断。本文提出了一种用于在线性时间内检测企业信息系统的管理漏洞和威胁的正式方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号