arrow
返回

A probabilistic relational model for security risk analysis

delete2010-09-01
delete53
PRE
AI
T
Teodor Sommestad *
M
Mathias Ekstedt
P
Pontus Johnson
DOI:10.1016/j.cose.2010.02.002delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Information system security risk, defined as the product of the monetary losses associated with security incidents and the probability that they occur, is a suitable decision criterion when considering different information system architectures. This paper describes how probabilistic relational models can be used to specify architecture metamodels so that security risk can be inferred from metamodel instantiations. A probabilistic relational model contains classes, attributes, and class-relationships. It can be used to specify architectural metamodels similar to class diagrams in the Unified Modeling Language. In addition, a probabilistic relational model makes it possible to associate a probabilistic dependency model to the attributes of classes in the architectural metamodel. This paper proposes a set of abstract classes that can be used to create probabilistic relational models so that they enable inference of security risk from instantiated architecture models. If an architecture metamodel is created by specializing the abstract classes proposed in this paper, the instantiations of the metamodel will generate a probabilistic dependency model that can be used to calculate the security risk associated with these instantiations. The abstract classes make it possible to derive the dependency model and calculate security risk from an instance model that only specifies assets and their relationships to each other. Hence, the person instantiating the architecture metamodel is not required to assess complex security attributes to quantify security risk using the instance model. (C) 2010 Elsevier Ltd. All rights reserved.
Keyword:
Security risk
Risk assessment
Architecture metamodel
Probabilistic relational model
Architecture analysis
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

R
Royal Institute of Technology
学者数:
1.8W
论文数: 1.8W
被引数: 25
引用论文

引用论文

The Implicit Positive and Negative Affect Test: Validity and Relationship with Cardiovascular Stress-Responses
err2016-03-30
err0
errOAAI
errMelanie M. van der Ploeg; Jos F. Brosschot; Julian F. Thayer; Bart Verkuil
err分享
err收藏
Characterization of microsatellite loci in Coffea arabica and related coffee species
err2001-12-25
err0
PREAI
errM. C. Combes; S. Andrzejewski; F. Anthony; B. Bertrand; P. Rovelli; G. Graziosi; P. Lashermes
err分享
err收藏
Teratogenicity of D-allulose
err2022-01-01
err0
errOAAI
errSoonok Sa; Yunji Seol; Albert W. Lee; Yong Heo; Hye-jung Kim; Chong Jin Park
err分享
err收藏
err
IF0
err
err0
PREAI
err
err分享
err收藏
RMS voltage sensor based on a variable parallel-plate capacitor made of electroplated copper
err2010-01-06
err0
PREAI
errJan Dittmer; Lars Hecht; Rolf Judaschke; Stephanus Büttgenbach
err分享
err收藏
err分享
err收藏
A model for evaluating IT security investments
err2004-07-01
err200
PREAI
errCavusoglu, H; Mishra, B; Raghunathan, S
err分享
err收藏
学者 查看更多内容