An Improved Information-Security Risk Assessment Algorithm for a Hybrid Model

Model-based assessment is of great significance to information-security risk assessment. This paper has proposed a risk assessment method of information security based on unified modeling language, risk assessment of attck tree analysis model. With the object-oriented and semi-formal model analysis,...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Veröffentlicht in:International journal of advancements in computing technology 2013-01, Vol.5 (2), p.250-257
1. Verfasser: Kong, Lin-jun
Format: Artikel
Sprache:eng
Schlagworte:
Online-Zugang:Volltext
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:Model-based assessment is of great significance to information-security risk assessment. This paper has proposed a risk assessment method of information security based on unified modeling language, risk assessment of attck tree analysis model. With the object-oriented and semi-formal model analysis, as well as description of relevant the security risk elements, we can conduct an in-depth analysis of the security risks assessment based on ATA models. On the condition of the analysis of the security events' impact to buinsses based on ETA, we can then improve the accuracy and objectivity of the risk assessment. The model-based approach is also beneficial to the risk assessment related factor model abstraction and reuse, as well as development of assessment tools and applications to improve the productivity of the risk assessment.
ISSN:2005-8039
2233-9337
DOI:10.4156/ijact.vol5.issue2.33