Agent-oriented software engineering
IEA/AIE '99 Proceedings of the 12th international conference on Industrial and engineering applications of artificial intelligence and expert systems: multiple approaches to intelligent systems
Hack I.T.: security through penetration testing
Hack I.T.: security through penetration testing
Introduction to Multiagent Systems
Introduction to Multiagent Systems
The essential synthesis of problem frames and assurance cases
Proceedings of the 2006 international workshop on Advances and applications of problem frames
A Systems Dynamics View of Security Assurance Issues: "The Curse of Complexity and Avoiding Chaos"
HICSS '09 Proceedings of the 42nd Hawaii International Conference on System Sciences
Multi-agent based security assurance monitoring system for telecommunication infrastructures
CNIS '07 Proceedings of the Fourth IASTED International Conference on Communication, Network and Information Security
Hi-index | 0.00 |
Today's IT systems are ubiquitous and take the form of small portable devices, to the convenience of the users. However, the reliance on this technology is increasing faster than the ability to deal with the simultaneously increasing threats to information security. This paper proposes metrics and a methodology for the evaluation of operational systems security assurance that take into account the measurement of security correctness of a safeguarding measure and the analysis of the security criticality of the context in which the system is operating i.e., where is the system used and/or what for?. In that perspective, the paper also proposes a novel classification scheme for elucidating the security criticality level of an IT system. The advantage of this approach lies in the fact that the assurance level fluctuation based on the correctness of deployed security measures and the criticality of the context of use of the IT system or device, could provide guidance to users without security background on what activities they may or may not perform under certain circumstances. This work is illustrated with an application based on the case study of a Domain Name Server DNS.