Considering Application Vulnerabilities in Risk Assessment and Management
نویسندگان
چکیده
The Haruspex suite is an integrated set of tools that adopts a scenario approach to automate ICT risk assessment and management. Each scenario includes an ICT infrastructure under attack by some intelligent attackers with some predefined goals. An attacker can reach its goals only by sequentially composing the attacks. This is the only strategy to overcome the infrastructure complexity and its large number of nodes. The suite applies a Monte Carlo method with multiple simulations of the attacker behavior to discover the sequences of each attacker. This simulation exploits a formal model of the target infrastructure that describes the infrastructure nodes, the vulnerabilities of the components these nodes run, and the logical topology. The multiple simulations of the Monte Carlo method support the discovering of alternative sequences and return a statistical sample of these sequences. This sample supports the computation of statistics to assess and manage the risk. This paper proposes an extension to the original model of the infrastructure to describe in a more accurate way how the implementation hierarchy and the interactions affect the attacks. After describing this extension, we show how it supports the modeling of web applications. In the end, we adopt the new model to assess a critical infrastructure that supervises and manages gas distribution.
منابع مشابه
The Assessment of the Community Capacity on the Urban Vulnerability Based on Community Disaster Risk Management (CBDRM) (Case Study : Yousef-Abad, Tehran City)
Disaster Management and current approaches in this field in one hand only has focused to physicalvulnerabilities and in the other hand has included consequential action to reduce vulnerability and improve physicalpreparation as well as resistance institutional insignificant during the disaster. Therefore, these approaches usually haveignored the capabilities and capacities of residents to reduc...
متن کاملThe recognition of the necessity of for community-based disaster risk management to reduce the risk of vulnerability to earthquake disaster (case study: YousefAbad neighborhood of Tehran)
Disaster management and current attitudes in this area only focus on this areachr('39')s physical vulnerabilities, raising urban residentschr('39') exposure to these challenges in front of the earthquake. On the other hand, Incidental actions include reducing the vulnerability and the physical strengthening and promotion of poor organization during the disaster; they ignored the capabilities an...
متن کاملApplication of Fuzzy and FEMA Modified Methods in Risk Assessment of Man-Made Threats in Water Systems
Bacground and objective: Assessing the threats and vulnerabilities of infrastructure is one of the major concerns of security officials in a country, and water supply systems are one of the most important and sensitive infrastructures. Water supply systems are also among the basic infrastructures that are very important in assessing the threats in these systems and identifying its weaknesses. I...
متن کاملUnderground transportation system risk assessment to mitigate vulnerability against natural disasters through intelligent urban management
Quantitative and qualitative monitoring and evaluation of risk management programs will play an important role in the development of Tehran metropolitan railway transport. Considering the tectonic studies, seismic zones, land degradation and faults in north and south of Tehran, the development of underground railway lines, the assessment of the vulnerability of subway stations and the escalatio...
متن کاملQuantitative Risk Assessment of Condensate Storage Tank, Considering Domino Effects
Introduction: In process industries, some of the primary events may result in secondary events in an industrial unit called the domino effect. Since refinery storage tanks are always at risk of fire and explosion, quantitative risk assessment is important in determining the severity and outcome of an accident, taking into account the effects of dominoes on the main industry, neighbors, and soci...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2016