DocumentCode :
2052195
Title :
A Visualisation Technique for the Identification of Security Threats in Networked Systems
Author :
Maple, Carsten ; Viduto, Valentina
Author_Institution :
Inst. for Res. in Applicable Comput., (IRAC), Univ. of Bedfordshire, Luton, UK
fYear :
2010
fDate :
26-29 July 2010
Firstpage :
551
Lastpage :
556
Abstract :
This paper is primarily focused on the increased IT complexity problem and the identification of security threats in networked systems. Modern networking systems, applications and services are found to be more complex in terms of integration and distribution, therefore, harder to be managed and protected. CIOs have to put their effort on threat´s identification, risk management and security evaluation processes. Objective decision making requires measuring, identifying and evaluating all enterprise events, either positive (opportunities) or negative (risks) and keeping them in perspective with the business objectives. Our approach is based on a visualisation technique that helps in decision making process, focusing on the threat identification using attack scenarios. For constructing attack scenarios we use the notion of attack graphs, as well as layered security approach. The proposed onion skin model combines attack graphs and security layers to illustrate possible threats and shortest paths to the attacker´s goal. By providing few examples we justify the advantage of the threat identification technique in decision making process.
Keywords :
computer network security; data visualisation; decision making; graph theory; risk management; IT complexity problem; attack graphs; layered security approach; networked systems; objective decision making process; onion skin model; risk management; security evaluation process; security layers; security threat identification; visualisation technique; Buildings; Data structures; Data visualization; Decision making; Risk management; Security; Skin; Attack graph; Attack tree; Onion skin model; Visualisation technique;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Visualisation (IV), 2010 14th International Conference
Conference_Location :
London
ISSN :
1550-6037
Print_ISBN :
978-1-4244-7846-0
Type :
conf
DOI :
10.1109/IV.2010.81
Filename :
5571147
Link To Document :
بازگشت