A Novel Security Risk Evaluation for Information Systems

  • Authors:
  • Zaobin Gan;Jiufei Tang;Ping Wu;Vijay Varadharajan

  • Affiliations:
  • -;-;-;-

  • Venue:
  • FCST '07 Proceedings of the 2007 Japan-China Joint Workshop on Frontier of Computer Science and Technology
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Quantitative security risk evaluation of information sys- tems is increasingly drawing more and more attention. This paper extends the attack tree model, and proposes a new quantitative risk evaluation method .While the risk value of the leaf node (atomic attack) is quantified, the multi- attribute utility theory is adopted. All algorithms are pre- sented for each steps of this new evaluation method. In ad- dition, a worked example is also experimented in this paper. The experimental result shows that the novel method can not only make the evaluation result more reasonable and objec- tive, but also offer a good foundation for the implementation of the automatic evaluation tool.