...
首页> 外文期刊>International journal of secure software engineering >Towards Ontological Approach to Security Risk Analysis of Information System: Model and Architecture
【24h】

Towards Ontological Approach to Security Risk Analysis of Information System: Model and Architecture

机译:面向本体的信息系统安全风险分析方法:模型与体系结构

获取原文
获取原文并翻译 | 示例
           

摘要

Resource allocation decisions can be enhanced by performing risk assessment during the early development phase. In order to improve and maintain the security of the Information System (IS, hereafter), there is need to build risk analysis model that can dynamically analyze threat data collected during the operational lifetime of the IS. In this paper the authors propose an ontological approach to accomplishing this goal. They present analyzer model and architecture, an agent-based risk analysis system (ARAS) which gathers identified threats events, probe them and correlates those using ontologies. It explores both quantitative and qualitative risk analysis techniques using real events data for probability predictions of threats based on an existing designed security ontology. To validate the feasibility of the approach a case study on e-banking system has been conducted. Simulated IDS output serves as input into the risk analysis system. The authors used JADE to implement the agents, protege OWL to create the ontology and ORACLE 11g SQL developer for the database. Optimistic results were obtained.
机译:通过在早期开发阶段进行风险评估,可以增强资源分配决策。为了改善和维护信息系统(IS,以下简称IS)的安全性,需要构建风险分析模型,该模型可以动态分析在IS的使用寿命期间收集的威胁数据。在本文中,作者提出了一种本体论方法来实现这一目标。他们介绍了分析器模型和体系结构,基于代理的风险分析系统(ARAS),该系统收集已识别的威胁事件,对其进行探测并使用本体将其关联起来。它基于现有的设计安全本体,使用真实事件数据探索威胁的概率预测,探索了定量和定性风险分析技术。为了验证该方法的可行性,对电子银行系统进行了案例研究。模拟的IDS输出用作风险分析系统的输入。作者使用JADE来实现代理,保护OWL来创建本体,并使用ORACLE 11g SQL开发该数据库。获得了乐观的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号