Knowledge-Based Framework for Real-Time Risk Assessment of Information Security Inspired by Danger Model

Author(s):  
Zhi-Hua Hu ◽  
Yong-Sheng Ding ◽  
Jing-Wen Huang
Author(s):  
Bogdan Korniyenko ◽  
Lilia Galata

In this article, the research of information system protection by ana­ ly­ zing the risks for identifying threats for information security is considered. Information risk analysis is periodically conducted to identify information security threats and test the information security system. Currently, various information risk analysis techni­ ques exist and are being used, the main difference being the quantitative or qualitative risk assessment scales. On the basis of the existing methods of testing and evaluation of the vulnerabilities for the automated system, their advantages and disadvantages, for the possibility of further comparison of the spent resources and the security of the information system, the conclusion was made regarding the deter­ mi­ nation of the optimal method of testing the information security system in the context of the simulated polygon for the protection of critical information resources. A simula­ tion ground for the protection of critical information resources based on GNS3 application software has been developed and implemented. Among the considered methods of testing and risk analysis of the automated system, the optimal iRisk methodology was identified for testing the information security system on the basis of the simulated. The quantitative method Risk for security estimation is considered. Generalized iRisk risk assessment is calculated taking into account the following parameters: Vulnerabili­ ty  — vulnerability assessment, Threat — threat assessment, Control — assessment of security measures. The methodology includes a common CVSS vul­ nerability assessment system, which allows you to use constantly relevant coefficients for the calculation of vulnerabilities, as well as have a list of all major vulnerabilities that are associated with all modern software products that can be used in the automated system. The known software and hardware vulnerabilities of the ground are considered and the resistance of the built network to specific threats by the iRisk method is calculated.


Author(s):  
Jie Bao ◽  
Xin Wang ◽  
Yihui Zheng ◽  
Feng Zhang ◽  
Xuyong Huang ◽  
...  

Author(s):  
Hailin Xiao ◽  
Wenqian Zhang ◽  
Wanying Li ◽  
Anthony Theodore Chronopoulos ◽  
Zhongshan Zhang

2008 ◽  
Vol 12 (sup2) ◽  
pp. 199-210 ◽  
Author(s):  
Dominik H. Lang ◽  
Sergio Molina-Palacios ◽  
Conrad D. Lindholm

Sign in / Sign up

Export Citation Format

Share Document