• DocumentCode
    3159628
  • Title

    iMeasure Security (iMS): A Novel Framework for Security Quantification

  • Author

    Vijayaraghavan, Vineeth ; Paul, Sanjoy

  • Author_Institution
    SETLabs, Infosys Technol. Ltd., Bangalore, India
  • fYear
    2009
  • fDate
    27-29 Dec. 2009
  • Firstpage
    414
  • Lastpage
    421
  • Abstract
    Given the dependence of today´s business systems on a network of computers and servers, the need for security is paramount. Furthermore, with the ever evolving nature of business, and the associated technology for supporting it, requirements for security are also evolving. Computers cannot protect information automatically. To guard information residing on the computers, security services and related technologies need to be applied. Security breaches are constantly changing, often at a speed that is difficult to measure. So security practices and procedures need to be reviewed, tested and upgraded on a constant basis, staying ahead of the game. One way of ensuring better security is to be able to measure its strength, and take steps to improve it in a continuous manner. Several standards are being developed that aim to certify the strength of a security system. However, these standards focus on qualitative evaluation of security level of a system and do not consider either the dynamic aspects of user behavior or the possible vulnerabilities and threats the system may be subjected to. Consequently, there is a need for an alternative quantitative modeling approach for security assessment that overcomes the above mentioned drawbacks of the existing systems. In this paper, we present an extensible framework called iMeasure Security (iMS) that is aimed at quantifying the security strength of an enterprise system and its business impact.
  • Keywords
    commerce; computer network security; computer network; enterprise system; iMeasure security; network server; qualitative evaluation; quantitative modeling; security assessment; security quantification; security system; Business communication; Communication system security; Computer networks; Computer security; Information security; Network servers; Protection; Standards development; Testing; Velocity measurement; Attack graph; Business impact; Likelihood estimation; Security quantification;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Networks and Communications, 2009. NETCOM '09. First International Conference on
  • Conference_Location
    Chennai
  • Print_ISBN
    978-1-4244-5364-1
  • Electronic_ISBN
    978-0-7695-3924-9
  • Type

    conf

  • DOI
    10.1109/NetCoM.2009.77
  • Filename
    5383971