Information Systems Security: Specification and Quantitative Evaluation

نویسندگان

  • Rodolphe Ortalo
  • Yves Deswarte
چکیده

This paper presents a method for the specification and evaluation of the security of information systems. This method is based on an extension of deontic logic, a formal language adapted for this task. First, we outline briefly the overall guidelines of the method and the various aspects of the security policy specification process. Then, the formalism is defined and extensions are proposed. To illustrate the use of this formalism, the paper presents how this method is applied to specify the security requirements of a real organization: a medium-size bank agency. In a second step, the paper focuses on the connection that can be established between this representation of the security needs of an organization and a methodology of quantitative evaluation of the operational security of the organization based on the privilege graph model. To illustrate the interest of these security measures, the security policy example introduced previously is used as a basis for applying the evaluation methodology taking into account some vulnerabilities of the bank agency.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Évaluation quantitative de la sécurité des systèmes d'information. (Quantitative Evaluation of Information Systems Security)

This dissertation presents a general method for the specification and quantitative evaluation of information systems security. This method allows to monitor the evolutions of an information system in operation, as well as to compare the impact on security of possible modifications of the functioning. It relies on a formal specification of the system security policy, augmented by a model of the ...

متن کامل

Evaluation of gray scale changes of CBCT system images in different axis using the DICOM file

The images of dental CBCT imaging systems used in conic shaped beams, stored in the DICOM format, have various applications in the dentistry, including bone density estimation to select the location of the orthodontic implant, bone loss detection and etc. In these systems, unlike CT imaging systems, the resulting images exhibit gray-scale non-uniformity in each of the different axis in FOV. Thi...

متن کامل

Quantitative evaluation of software security: an approach based on UML/SecAM and evidence theory

Quantitative and model-based prediction of security in the architecture design stage facilitates early detection of design faults hence reducing modification costs in subsequent stages of software life cycle. However, an important question arises with respect to the accuracy of input parameters. In practice, security parameters can rarely be estimated accurately due to the lack of sufficient kn...

متن کامل

On the design and security of a lattice-based threshold secret sharing scheme

In this paper, we introduce a method of threshold secret sharing scheme (TSSS) in which secret reconstruction is based on Babai's nearest plane algorithm. In order to supply secure public channels for transmitting shares to parties, we need to ensure that there are no quantum threats to these channels. A solution to this problem can be utilization of lattice-based cryptosystems for these channe...

متن کامل

امنیت اطلاعات سامانه های تحت وب نهاد کتابخانه های عمومی کشور

Purpose: This paper aims to evaluate the security of web-based information systems of Iran Public Libraries Foundation (IPLF). Methodology: Survey method was used as a method for implementation. The tool for data collection was a questionnaire, based on the standard ISO/IEC 27002, that has the eleven indicators and 79 sub-criteria, which examines security of web-based information systems of IP...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 1997