Modeling and Managing Risk in Billing Infrastructures

نویسندگان

  • Fabrizio Baiardi
  • Claudio Telmon
  • Daniele Sgandurra
چکیده

This paper discusses risk modeling and risk management in information and communications technology (ICT) systems for which the attack impact distribution is heavy tailed (e.g., power law distribution) and the average risk is unbounded. Systems with these properties include billing infrastructures used to charge customers for services they access. Attacks against billing infrastructures can be classified as peripheral attacks and backbone attacks. The goal of a peripheral attack is to tamper with user bills; a backbone attack seeks to seize control of the billing infrastructure. The probability distribution of the overall impact of an attack on a billing infrastructure also has a heavy-tailed curve. This implies that the probability of a massive impact cannot be ignored and that the average impact may be unbounded – thus, even the most expensive countermeasures would be cost effective. Consequently, the only strategy for managing risk is to increase the resilience of the infrastructure by employing redundant components.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

An efficient non-repudiation billing protocol in heterogeneous 3G-WLAN networks

The wireless communication with delivering variety of services to users is growing rapidly in recent years. The third generation of cellular networks (3G), and local wireless networks (WLAN) are the two widely used technologies in wireless networks. 3G networks have the capability of covering a vast area; while, WLAN networks provide higher transmission rates with less coverage. Since the two n...

متن کامل

Designing Models and Systems to Support IT Management: A Case for Multilevel Modeling

Refering to the domain of IT management, this paper demonstrates conceptual strengths and economic benefits of multilevel modeling. In the past, IT management was primarily focussed on technical aspects of IT infrastructures. In recent years, more and more organizations became aware of the pivotal relevance their IT infrastructures has for staying competitive. Therefore, IT managers are expecte...

متن کامل

Exploration du concept d ’ Infrastructures en tant que Services avec HIPerNET

With the expansion and convergence of communication and computing, dynamic provisioning of customized networking and processing infrastructures, as well as resource virtualization, are appealing concepts and technologies. Therefore, new models and tools are needed to allow users to create, trust and enjoy such on-demand virtual infrastructures within a wide area context. This research report pr...

متن کامل

A Three-dimensional Numerical Modeling of Contaminant Dispersion from Arvand Rood River into the Persian Gulf

The Persian Gulf is an important economic and geo-political region. Owing to its oil and gas resources, it is one of the busiest waterways in the world. There are many operating oil wells in the northern part of the Persian Gulf . As a result, the risk of contaminant dispersion is high. The deliberate discharge of 6.3 million barrels of crude oil during the 1991 war against Kuwait in this regio...

متن کامل

Model-driven risk analysis of evolving critical infrastructures

The protection and security of critical infrastructures are important parts of Homeland Defense. Adequate means for analyzing the security risks of such infrastructures is a prerequisite for properly understanding the security needs and for maintaining appropriate incident preparedness. Risk management is coordinated activities to direct and control an organization with regard to risk, and incl...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2009