DocumentCode :
3159628
Title :
iMeasure Security (iMS): A Novel Framework for Security Quantification
Author :
Vijayaraghavan, Vineeth ; Paul, Sanjoy
Author_Institution :
SETLabs, Infosys Technol. Ltd., Bangalore, India
fYear :
2009
fDate :
27-29 Dec. 2009
Firstpage :
414
Lastpage :
421
Abstract :
Given the dependence of today´s business systems on a network of computers and servers, the need for security is paramount. Furthermore, with the ever evolving nature of business, and the associated technology for supporting it, requirements for security are also evolving. Computers cannot protect information automatically. To guard information residing on the computers, security services and related technologies need to be applied. Security breaches are constantly changing, often at a speed that is difficult to measure. So security practices and procedures need to be reviewed, tested and upgraded on a constant basis, staying ahead of the game. One way of ensuring better security is to be able to measure its strength, and take steps to improve it in a continuous manner. Several standards are being developed that aim to certify the strength of a security system. However, these standards focus on qualitative evaluation of security level of a system and do not consider either the dynamic aspects of user behavior or the possible vulnerabilities and threats the system may be subjected to. Consequently, there is a need for an alternative quantitative modeling approach for security assessment that overcomes the above mentioned drawbacks of the existing systems. In this paper, we present an extensible framework called iMeasure Security (iMS) that is aimed at quantifying the security strength of an enterprise system and its business impact.
Keywords :
commerce; computer network security; computer network; enterprise system; iMeasure security; network server; qualitative evaluation; quantitative modeling; security assessment; security quantification; security system; Business communication; Communication system security; Computer networks; Computer security; Information security; Network servers; Protection; Standards development; Testing; Velocity measurement; Attack graph; Business impact; Likelihood estimation; Security quantification;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Networks and Communications, 2009. NETCOM '09. First International Conference on
Conference_Location :
Chennai
Print_ISBN :
978-1-4244-5364-1
Electronic_ISBN :
978-0-7695-3924-9
Type :
conf
DOI :
10.1109/NetCoM.2009.77
Filename :
5383971
Link To Document :
بازگشت