Security based survivability risk analysis with extended HQPN

  • Authors:
  • Hyunsang Youn;Cheolhyun Park;Eunseok Lee

  • Affiliations:
  • Sungkyunkwan University, Suwon, Republic of Korea;Sungkyunkwan University, Suwon, Republic of Korea;Sungkyunkwan University, Suwon, Republic of Korea

  • Venue:
  • Proceedings of the 5th International Conference on Ubiquitous Information Management and Communication
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

Analysis of software survivability in the early development phase is very important to validate and specify software architecture. Specifically, quantitative evaluation of survivability is very useful to determine the architecture and to estimate the risk. The risk factor can be quantified as a combination of the probability that a software system may be failed through security threat and the severity of the damages caused by the attack. In this paper, we devise a methodology for analysis of risk factor which originates from violations of security goal. We elaborate Extended Hierarchically combined Queueing Petri Nets (E-HQPN) to estimate the survival failure probability with regard to attack and combines it with the severity of the failure consequence obtained using the Functional Failure Analysis. We apply the methodology on the development of an e-business application using step-by-step approach.