Real-Time Security Monitoring of Interdependent Services in Critical Infrastructures. Case study of a Risk-Based Approach
نویسندگان
چکیده
In today’s world, where most of the critical infrastructures (CIs) are based on distributed systems, security failures have become very common, even within large corporations. The critical infrastructures are tightly interconnected, mutually dependent, and are exposed everyday to new risks. These (inter)dependencies generate potential cascading effects that may spread a malfunction or an attack from one part of the system to another dependent infrastructure. In this paper, we propose a risk-based methodology that aims to monitor interdependent services based on generic risks and assurance levels using the classical security properties: confidentiality, integrity and availability (C,I,A). This allows to determine the security state of a critical infrastructure service, taking it’s dependencies to other services into account. Furthermore, our approach allows to monitor the system state on-line during system operation. Monitoring of the security state of a service helps to determine the quality of the provided service (QoS) and allows each CI provider to react and adopt the best behaviour corresponding to the security status of its different services.
منابع مشابه
Approach for Monitoring and Measurement of Interdependent Services in Critical Infrastructures
This paper presents a systematic approach for computing metrics and performance indices of interdependent critical infrastructures based on their information content, expert views and risk analysis capabilities. The paper also proposes a risk-based methodology that aims to monitor interdependent services based on generic risks and assurance levels using security properties: confidentiality, int...
متن کاملAssessment of BAM with ANP Approach; Case Study: Bank Sepah
In today's business environment in which coordination and adaptation with constant changes are the only ways of survival, real-time monitoring of activities and making the decisions accordingly are necessary. Since performance measurement cannot be managed independent of business processes, Business Activity Monitoring (BAM) systems should monitor performance metrics based on business processes...
متن کاملAssessment of BAM with ANP Approach; Case Study: Bank Sepah
In today's business environment in which coordination and adaptation with constant changes are the only ways of survival, real-time monitoring of activities and making the decisions accordingly are necessary. Since performance measurement cannot be managed independent of business processes, Business Activity Monitoring (BAM) systems should monitor performance metrics based on business processes...
متن کاملSupport Tool for a Bayesian Network Based Critical Infrastructure Risk Model
Critical infrastructures (CIs) provide important services to society and economy, like electricity, or communication networks to enable telephone calls and internet access. CI services are expected to provide safety and security features like data Confidentiality and Integrity as well as to ensure service Availability (CIA). The complexity and interdependency of CI services makes it hard for CI...
متن کاملCritical Success Factors in implementing information security governance (Case study: Iranian Central Oil Fields Company)
The oil industry, as one of the main industries of the country, has always faced cyber attacks and security threats. Therefore, the integration of information security in corporate governance is essential and a governance challenge. The integration of information security and corporate governance is called information security governance. In this research, we identified "critical success factor...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2010