• DocumentCode
    241460
  • Title

    Defining threats across organizational boundaries

  • Author

    Pramanik, Sarah ; Snider, Dallas H.

  • Author_Institution
    Northrop Grumman Corp., Bethpage, NY, USA
  • fYear
    2014
  • fDate
    29-30 Oct. 2014
  • Firstpage
    1
  • Lastpage
    5
  • Abstract
    Threats against systems are continually changing and evolving. The ability to secure systems against them is an ongoing battle. One of the most difficult responsibilities that security experts face is the need to take the intangible threats and complex security information and explain it to stakeholders with enough clarity as to allow for decision making. There are typically, multiple levels of stakeholders, needing various levels of brevity or insight in order to react to the information. The Chief Executive Officer (CEO) needs brevity, the lead security engineer needs enough information in order to make technical trade-offs.Both Bayesian networks and concept mapping are based on patterns. They both look to provide insight into information based on pattern relations. Bayesian networks provide a method to look at the probabilities associated with events occurring. Concept maps show perceived regularities in events or objects by the use of labels. The use of concept maps has been shown to provide a means of describing complex ideas in a simple manner, such as is necessary when dealing with higher levels of management. Bayesian networks can be used to describe the detailed probabilities of something occurring, as is useful when working with engineers. The purpose of this paper is to show how the hybrid use of concept maps and Bayesian networks to outline the same information can be useful for providing threat information across organizational boundaries.
  • Keywords
    belief networks; probability; security of data; Bayesian network; chief executive officer; complex security information; concept mapping; intangible threats; organizational boundaries; probabilities; secure systems; Bayes methods; Computer security; Education; Grippers; Organizations; Probabilistic logic; Bayesian Network; Concept Map; organization; threat;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Emerging Technologies for a Smarter World (CEWIT), 2014 11th International Conference & Expo on
  • Conference_Location
    Melville, NY
  • Type

    conf

  • DOI
    10.1109/CEWIT.2014.7021152
  • Filename
    7021152