DocumentCode
3159628
Title
iMeasure Security (iMS): A Novel Framework for Security Quantification
Author
Vijayaraghavan, Vineeth ; Paul, Sanjoy
Author_Institution
SETLabs, Infosys Technol. Ltd., Bangalore, India
fYear
2009
fDate
27-29 Dec. 2009
Firstpage
414
Lastpage
421
Abstract
Given the dependence of today´s business systems on a network of computers and servers, the need for security is paramount. Furthermore, with the ever evolving nature of business, and the associated technology for supporting it, requirements for security are also evolving. Computers cannot protect information automatically. To guard information residing on the computers, security services and related technologies need to be applied. Security breaches are constantly changing, often at a speed that is difficult to measure. So security practices and procedures need to be reviewed, tested and upgraded on a constant basis, staying ahead of the game. One way of ensuring better security is to be able to measure its strength, and take steps to improve it in a continuous manner. Several standards are being developed that aim to certify the strength of a security system. However, these standards focus on qualitative evaluation of security level of a system and do not consider either the dynamic aspects of user behavior or the possible vulnerabilities and threats the system may be subjected to. Consequently, there is a need for an alternative quantitative modeling approach for security assessment that overcomes the above mentioned drawbacks of the existing systems. In this paper, we present an extensible framework called iMeasure Security (iMS) that is aimed at quantifying the security strength of an enterprise system and its business impact.
Keywords
commerce; computer network security; computer network; enterprise system; iMeasure security; network server; qualitative evaluation; quantitative modeling; security assessment; security quantification; security system; Business communication; Communication system security; Computer networks; Computer security; Information security; Network servers; Protection; Standards development; Testing; Velocity measurement; Attack graph; Business impact; Likelihood estimation; Security quantification;
fLanguage
English
Publisher
ieee
Conference_Titel
Networks and Communications, 2009. NETCOM '09. First International Conference on
Conference_Location
Chennai
Print_ISBN
978-1-4244-5364-1
Electronic_ISBN
978-0-7695-3924-9
Type
conf
DOI
10.1109/NetCoM.2009.77
Filename
5383971
Link To Document