Risk profiles and distributed risk assessment

نویسندگان

  • Howard Chivers
  • John A. Clark
  • Pau-Chen Cheng
چکیده

Risk assessment is concerned with discovering threat paths between potential attackers and critical assets, and is generally carried out during a system’s design and then at fixed intervals during its operational life. However, the currency of such analysis is rapidly eroded by system changes; in dynamic systems these include the need to support ad-hoc collaboration, and dynamic connectivity between the system’s components. This paper resolves these problems by showing how risks can be assessed incrementally as a system changes, using risk profiles, which characterize the risk to a system from subverted components. We formally define risk profiles, and show that their calculation can be fully distributed; each component is able to compute its own profile from neighbouring information. We further show that profiles converge to the same risks as systematic threat path enumeration, that changes in risk are efficiently propagated throughout a distributed system, and that the distributed computation provides a criterion for when the security consequences of a policy change are local to a component, or will propagate into the wider system. Risk profiles have the potential to supplement conventional risk assessments with useful new metrics, maintain accurate continuous assessment of risks in dynamic distributed systems, link a risk assessment to the wider environment of the system, and evaluate defence-in-depth strategies. a 2009 Elsevier Ltd. All rights reserved.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Comparison of ergonomic risk assessment results from Quick Exposure Check and Rapid Entire Body Assessment in an anodizing industry of Tehran, Iran

 Background: The aim of this paper was the comparison of ergonomic risk assessment results (final score and action levels) for the entire body as determined using Quick Exposure Check (QEC) and Rapid Entire Body Assessment (REBA).  Materials and Methods: This was a cross-sectional study in which all 82 workers engaged in various processes with different activities in an anodizing a...

متن کامل

A risk model for cloud processes

Traditionally, risk assessment consists of evaluating the probability of "feared events", corresponding to known threats and attacks, as well as these events' severity, corresponding to their impact on one or more stakeholders. Assessing risks of cloud-based processes is particularly difficult due to lack of historical data on attacks, which has prevented frequency-based identification...

متن کامل

Risk Assessment of Phthalate Compounds in Bottled Water Consumed in Isfahan, Iran

Background: Phthalates are main ingredients of polyethylene terephthalate (PET) bottles used for storage of water. These compounds can cause adverse effects on human health. The purpose of this study was the quantification of the amounts of phthalates migrated in bottled water as well as the risk assessment of those compounds. Methods: This cross sectional study was performed on 15 PET bottled...

متن کامل

Presenting a semi-quantitative model based on the resiliency engineering management commitment index in assessing the level of preparedness against emergency situations of hospitals in a fuzzy environment (case study: selected Faraja hospitals in 202

Abstract Background and Objective: The main index in resilience engineering is the management commitment index. In this study, a semi-quantitative risk assessment method based on the fuzzy hierarchical analysis method for management commitment index was implemented in evaluating the resilience level of two selected hospitals. Materials and methods: At first, evaluation tools including a 17-qu...

متن کامل

Applicable risk assessment methods in occupational and environmental exposure to nanoparticles - a narrative review

Nanoparticles (NPs) are a heterogeneous group of materials that have various applications, and their risk assessment is an essential condition. This study aimed to review the applicable risk assessment methods in occupational and environmental exposures to NPs. A literature search for articles published since 2005 in Web of Knowledge, Scopus, PubMed, Science Direct, and Google Scholar, using ap...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • Computers & Security

دوره 28  شماره 

صفحات  -

تاریخ انتشار 2009