A quantitative risk analysis approach for deliberate threats

  • Authors:
  • Nikos Vavoulas;Christos Xenakis

  • Affiliations:
  • Department of Digital Systems, University of Piraeus, Greece;Department of Digital Systems, University of Piraeus, Greece

  • Venue:
  • CRITIS'10 Proceedings of the 5th international conference on Critical Information Infrastructures Security
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Recently, organizations around the world are becoming aware of the need to run risk management programs in order to enhance their information security. However, the majority of the existing qualitative/empirical methods fail to adhere to the terminology defined by ISO 27000-series and treat deliberate threats in a misleading way. In this paper, a quantitative risk analysis approach for deliberate threats is introduced. The proposed approach follows the steps suggested by the ISO 27005 standard for risk management, extending them in order to focus on deliberate threats and the different information security incidents that realize them. It is based on three-levels: the conceptual foundation level, the modeling tools level and the mathematical foundation level. The conceptual foundation level defines and analyzes the terminology involved, using unified modeling language (UML) class diagrams. The modeling tools level introduces certain tools that assist in modeling the relations among different concepts. Finally, the mathematical foundation level includes all the different mathematical formulas and techniques used to estimate risk values for each threat.