首页> 外文OA文献 >Probabilistic Risk Assessment for Security Requirements: A Preliminary Study
【2h】

Probabilistic Risk Assessment for Security Requirements: A Preliminary Study

机译:安全概率风险评估 要求:初步研究

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Risk assessment is a critical decision making process during the Security Certification and Accreditation (C\u26A) process. However, existing infrastructure-wide C\u26A processes in real world are challenged by the ever increasing complexity of information systems and their diverse socio-technical operational environments. The lack of an explicit model and the associated uncertainties of software behavior are two main reasons that directly impact the effectiveness of risk assessment as well as the subjective decisions made based on the different level of domain expertise. In this paper, we propose a method for a probabilistic model driven risk assessment on security requirements. The security requirements and their causal relationships are represented using MEBN (Multi-Entities Bayesian Networks) logic that constructs an explicit formal risk assessment model that supports evidence-driven arguments. The proposed approach is described by using real-world C\u26A scenarios to show not only its feasibility for security requirements risk assessment but also its effectiveness for the sensitivity analysis to identify critical influences among information entities in a complex and uncertain operational environment.
机译:风险评估是安全认证和鉴定(C \ u26A)过程中的关键决策过程。但是,现实世界中现有的基础架构范围的C \ u26A流程面临着信息系统及其日益多样化的社会技术操作环境日益复杂化的挑战。缺乏明确的模型以及相关的软件行为不确定性是直接影响风险评估以及基于不同领域专业知识水平做出的主观决策的两个主要原因。在本文中,我们提出了一种基于概率模型的安全需求风险评估方法。安全需求及其因果关系使用MEBN(多实体贝叶斯网络)逻辑表示,该逻辑构建了一个明确的正式风险评估模型,该模型支持证据驱动的论证。通过使用实际C \ u26A方案描述了所提出的方法,不仅显示了其在安全需求风险评估中的可行性,而且还显示了其在敏感度分析中识别复杂和不确定操作环境中的信息实体之间的关键影响的有效性。

著录项

  • 作者

    Lee, Seok-Won;

  • 作者单位
  • 年度 2011
  • 总页数
  • 原文格式 PDF
  • 正文语种
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号