arrow
Return

A Model For risk-Based adaptive security controls

delete2022-04-01
delete8
delete
OA
AI
M
Miguel Calvo
M
Marta Beltrán *
DOI:10.1016/j.cose.2022.102612delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Security controls and countermeasures have shifted from static desktop-based and corporate network environments to heterogeneous, distributed and dynamic environments (e.g., cloud and mobile computing or Internet of Things). Due to this paradigm shift, adaptive and risk-based approaches have gained significant importance. These approaches allow security managers to perform context-aware decision making, adapting controls' deployment, configuration or use to every specific situation, depending on the current value of risk indicators or scores and on the level of risk tolerated by the organisation at any given time. This paper proposes a model to automatically adapt security controls to different risk scenarios in almost real-time (if required). This model is based on a three-layer architecture and a three-step flow (measurement-decision-adaptation), relying on a scalable policies&rules framework capable of integrating with different kinds of controls. Furthermore, the proposed model is validated and evaluated with an actual use case. (C) 2022 The Authors. Published by Elsevier Ltd.
Keywords:
Adaptive security
Context-aware decision making
Dynamic security controls
MAPE Loop
Risk-based security
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

U
Universidad Rey Juan Carlos
Scholars:
6.1K
Papers: 6.1K
Citations: 6.7K