Risk-based Systems Security Engineering: Stopping Attacks with Intention

  • Authors:
  • Shelby Evans;David Heinbuch;Elizabeth Kyule;John Piorkowski;James Wallner

  • Affiliations:
  • BBN;APL;APL;APL;CDA

  • Venue:
  • IEEE Security and Privacy
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

Government and industry increasingly rely on modern information systems (IS) for mission successes. But their critical IS must survive in hostile environments; thus, mission owners need systems security engineers to build systems that are secure against real-world attacks but not over-engineered against a particular one. By understanding which attacks are most likely and which risks are most serious, mission owners can make cost-effective countermeasures decisions. We describe a systems security-engineering methodology for enumerating system attacks, assessing risks, and choosing countermeasures that best mitigate the risks.