[go: up one dir, main page]
More Web Proxy on the site http://driver.im/ skip to main content
article

Security Assurance Evaluation and IT Systems' Context of Use Security Criticality

Published: 01 October 2011 Publication History

Abstract

Today's IT systems are ubiquitous and take the form of small portable devices, to the convenience of the users. However, the reliance on this technology is increasing faster than the ability to deal with the simultaneously increasing threats to information security. This paper proposes metrics and a methodology for the evaluation of operational systems security assurance that take into account the measurement of security correctness of a safeguarding measure and the analysis of the security criticality of the context in which the system is operating i.e., where is the system used and/or what for?. In that perspective, the paper also proposes a novel classification scheme for elucidating the security criticality level of an IT system. The advantage of this approach lies in the fact that the assurance level fluctuation based on the correctness of deployed security measures and the criticality of the context of use of the IT system or device, could provide guidance to users without security background on what activities they may or may not perform under certain circumstances. This work is illustrated with an application based on the case study of a Domain Name Server DNS.

References

[1]
Alberts, C. J.,&Dorofee, A. J. 2001. OCTAVE criteria, version 2.0 Tech. Rep. No. CMU/SEI-2001-TR-016. Pittsburgh, PA: Carnegie Mellon University.
[2]
Bulut, E., Khadraoui, D.,&Marquet, B. 2007. Multi-agent based security assurance monitoring system for telecommunication infrastructures. In Proceedings of the Fourth IASTED International Conference on Communication, Network and Information Security pp. 90-95.
[3]
Common Criteria. 2006. Common criteria for information technology, part 1: Introduction and general model version 3.1. Retrieved from http://www.commoncriteriaportal.org/files/ccfiles/CCPART1V3.1R1.pdf
[4]
Evans, D. L., Bond, P. J.,&Bement, A. L. 2004. Standards for security categorization of federal information and information systems. Gaithersburg, MD: NIST.
[5]
Holstein, D. K. 2009. A systems dynamics view of security assurance issues: The curse of complexity and avoiding chaos. In Proceedings of the 42nd Hawaii International Conference on System Sciences pp. 1-9.
[6]
International Organization for Standardization. 2009. ISO/IEC 27004: Information technology - Security techniques - Information security management measurements. Geneva, Switzerland: International Organization for Standardization.
[7]
Jansen, W. 2009. Directions in security metrics research Tech. Rep. No. NISTIR7564. Gaithersburg, MD: National Institute of Standards and Technology.
[8]
Jennings, N. R. 1999. An agent-based software engineering. In Proceedings of the 9th European Workshop on Modelling Autonomous Agents in a Multi-Agent World.
[9]
Klevinsky, T. J., Laliberte, S.,&Gupta, A. 2002. Hack I.T.-Security through penetration testing. Reading, MA: Addison-Wesley.
[10]
Le Grand, C. H. 2005. Software security assurance: A framework for software vulnerability management and audit. Longwood, FL: CHL Global Associates and Ounce Labs, Inc.
[11]
Mouratidis, H.,&Giorgini, P. 2007. Secure Tropos: A security-oriented extension of the tropos methodology. International Journal of Software Engineering and Knowledge Engineering, 172, 285-309.
[12]
OLF. 2009. OLF Guideline No 123: Classification of process control, safety and support ICT systems based on criticality. Retrieved from http://www.olf.no/Documents/Retningslinjer/100-127/123%20-%20Classification%20of%20process%20control,%20safety%20and%20support.pdf?epslanguage=no
[13]
Ouedraogo, M., Mouratidis, H., Khadraoui, D.,&Dubois, E. 2009. A probe capability metric taxonomy for assurance evaluation. In Proceedings of the UEL's AC&T Conference.
[14]
Ouedraogo, M., Savola, R., Mouratidis, H., Preston, D., Khadraoui, D.,&Dubois, E. 2010. Taxonomy of quality metrics for security verification process. Journal of Software Quality.
[15]
Savola, R. M. 2007. Towards a taxonomy for information security metrics. In Proceedings of the International Conference on Software Engineering Advances, Cap Esterel, France.
[16]
Seddigh, N., Pieda, P., Matrawy, A., Nandy, B., Lambadaris, L.,&Hatfield, A. 2004. Current trends and advances in information assurance metrics. In Proceedings of the Conference on Privacy, Trust Management and Security pp. 197-205.
[17]
Stoneburner, G. 2001. Underlying technical models for information technology security. Gaithersburg, MD: National Institute of Standards and Technology.
[18]
Strunk, E. A.,&Knight, J. C. 2006, May 23. The essential synthesis of problem frames and assurance cases. In Proceedings of the Second International Workshop on Applications and Advances in Problem Frames.
[19]
Swanson, M., Nadya, B., Sabato, J., Hash, J.,&Graffo, L. 2003. Security metrics guide for information technology systems Tech. Rep. No. NIST-800-55. Gaithersburg, MD: National Institute of Standards and Technology.
[20]
Vaughn, R. B., Henning, R.,&Siraj, A. 2002. Information assurance measures and metrics - state of practice and proposed taxonomy. In Proceedings of the IEEE International Hawaii Conference on System Sciences p. 331.3.
[21]
Wool, A. 2004. A quantitative study of firewall configuration errors. Computer, 376, 62-67.
[22]
Wooldridge, M. 2002. An introduction to multi-agent systems. New York, NY: John Wiley&Sons.
  1. Security Assurance Evaluation and IT Systems' Context of Use Security Criticality

    Recommendations

    Comments

    Please enable JavaScript to view thecomments powered by Disqus.

    Information & Contributors

    Information

    Published In

    cover image International Journal of Handheld Computing Research
    International Journal of Handheld Computing Research  Volume 2, Issue 4
    October 2011
    94 pages
    ISSN:1947-9158
    EISSN:1947-9166
    Issue’s Table of Contents

    Publisher

    IGI Global

    United States

    Publication History

    Published: 01 October 2011

    Author Tags

    1. Assurance Metrics
    2. Criticality
    3. Security Assurance
    4. Security Management
    5. Security Verification

    Qualifiers

    • Article

    Contributors

    Other Metrics

    Bibliometrics & Citations

    Bibliometrics

    Article Metrics

    • 0
      Total Citations
    • 0
      Total Downloads
    • Downloads (Last 12 months)0
    • Downloads (Last 6 weeks)0
    Reflects downloads up to 13 Dec 2024

    Other Metrics

    Citations

    View Options

    View options

    Media

    Figures

    Other

    Tables

    Share

    Share

    Share this Publication link

    Share on social media