eTVRA, a Threat, Vulnerability and Risk Assessment Method and Tool for eEurope

  • Authors:
  • Judith E. Y. Rossebo;Scott Cadzow;Paul Sijben

  • Affiliations:
  • NTNU, Department of Telematics, Norway;Cadzow Communications (C3L), 10 Yewlands;EemValley Technology, Contrabaserf, Netherlands

  • Venue:
  • ARES '07 Proceedings of the The Second International Conference on Availability, Reliability and Security
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

The telecommunications environment is evolving into Next Generation Networks (NGN). On an NGN, telecommunications services are recreated on IP networks, this creates a demand on standardization bodies to adapt and meet the needs of these emerging networks. Securing the service environment for eBusiness and the underlying network are crucial areas cited in the eEurope action plan [1]. Standardization provides an important means for securing the NGN and establishing trust in its services and infrastructure in order to enable the development of modern public services. In response to this, we have developed a threat, vulnerability and risk assessment (eTVRA) method and tool for use in standardisation. Using the eTVRA method and tool, the threats to NGNs can be analyzed and a set of recommended countermeasures identified that when implemented will reduce the overall risk to users of NGNs. In this paper we present the eTVRA method and tool along with the results of its application to the use of Enhanced Number (ENUM) [2] and SIP [17] in the NGN.