首页> 外文期刊>Arabian Journal for Science and Engineering. Section A, Sciences >An Ontology-Based Security Risk Management Model for Information Systems
【24h】

An Ontology-Based Security Risk Management Model for Information Systems

机译:信息系统的本体安全风险管理模型

获取原文
获取原文并翻译 | 示例
           

摘要

Security risk management is a knowledge-intensive procedure that requires monitoring and capturing relevant information that can assist in making the right decision by managers. In this paper, a semantically enhanced model for security management during the information system lifetime is proposed. The model supports the continuous collection of identified threat behaviours from the intrusion detection system, filtering and analysis of the threats within a time snapshot and re-appraiser of IS security countermeasures which involves the security administrator (S-Admin), managers, IS and security management system as stakeholders. The probe agent categorizes the security threats identified by the IDS using the developed ontology-driven knowledge base, while the likelihood of threats occurring in real time was obtained using long-term frequency probability. The case-based reasoning paradigm is employed for the security solution reasoning of identified threat risk. The suggested security solutions are based on CASE base built on existing threat ontology. The re-appraiser is based on the success likelihood of potential ongoing threats. The system facilitates management decision with regard to security control selection so that they can have a maximum Return on Security Investment. The proposed Collect–Probe–Analyse–Reason–Reappraise model is illustrated using an e-banking system.
机译:安全风险管理是一种知识密调的程序,需要监测和捕获有助于管理经理做出正确决定的相关信息。在本文中,提出了一种在信息系统生命周期期间的用于安全管理的语义增强模型。该模型支持从入侵检测系统,过滤和分析时间快照和重新评估师的威胁的持续收集所识别的威胁行为的连续收集是安全对策,这涉及安全管理员(S-admin),管理者,是和安全的安全对策管理系统作为利益相关者。探测剂对IDS识别的安全威胁使用开发的本体驱动的知识库分类,而使用长期频率概率获得实时发生的威胁的可能性。基于案例的推理范例用于识别威胁风险的安全解决方案推理。建议的安全解决方案基于基于现有威胁本体的案例基础。重新评估师基于潜在持续威胁的成功可能性。该系统有助于在安全控制选择方面提供管理决策,以便他们可以最大限度地回报安全投资。使用电子银行系统说明所提出的收集探针分析 - Reappraise模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号