Quantitative Evaluation and Reevaluation of Security in Services
نویسندگان
چکیده
Services are software components or systems designed to support interoperable machine or application-oriented interaction over a network. The popularity of services grows because they are easily accessible, very flexible, provide reach functionality, and can constitute more complex services. During the service selection, the user considers not only functional requirements to a service but also security requirements. The user would like to be aware that security of the service satisfies security requirements before starting the exploitation of the service, i.e., before the service is granted to access assets of the user. Moreover, the user wants to be sure that security of the service satisfies security requirements during the exploitation which may last for a long period. Pursuing these two goals require security of the service to be evaluated before the exploitation and continuously reevaluated during the exploitation. This thesis aims at a framework consisting of several quantitative methods for evaluation and continuous reevaluation of security in services. The methods should help a user to select a service and to control the service security level during the exploitation. The thesis starts with the formal model for general quantitative security metrics and for risk that may be used for the evaluation of security in services. Next, we adjust the computation of security metrics with a refined model of an attacker. Then, the thesis proposes a general method for the evaluation of security of a complex service composed from several simple services using different security metrics. The method helps to select the most secure design of the complex service. In addition, the thesis describes an approach based on the Usage Control (UCON) model for continuous reevaluation of security in services. Finally, the thesis discusses several strategies for a cost-effective decision making in the UCON under uncertainties.
منابع مشابه
Quantitative evaluation of software security: an approach based on UML/SecAM and evidence theory
Quantitative and model-based prediction of security in the architecture design stage facilitates early detection of design faults hence reducing modification costs in subsequent stages of software life cycle. However, an important question arises with respect to the accuracy of input parameters. In practice, security parameters can rarely be estimated accurately due to the lack of sufficient kn...
متن کاملReevaluation of problems and challenges in Iran University of Medical Sciences, the first step to an effective performance improvement
Background: In Iran, medical universities are responsible for providing medical education and health services as well as maintaining and improving population health through scientific and innovative methods. Identifying problems and challenges that hinder universities’ performance, and supporting them with innovative problem solving methods can help managers in achieving university goals. Rreco...
متن کاملEvaluation of factors influencing patient satisfaction in social security hospitals in Mazandaran province, North of Iran
Abstract Background: Patient satisfaction is affected by hospital services and may have an effect on the cultural, social and personal conditions of the people living in the region. This research aimed to evaluate the patient satisfaction in social security hospitals in Mazandaran province. Methods: From Spring 2012 to Summer 2013, all patients admitted to social security hospitals in Maza...
متن کاملFormal approach on modeling and predicting of software system security: Stochastic petri net
To evaluate and predict component-based software security, a two-dimensional model of software security is proposed by Stochastic Petri Net in this paper. In this approach, the software security is modeled by graphical presentation ability of Petri nets, and the quantitative prediction is provided by the evaluation capability of Stochastic Petri Net and the computing power of Markov chain. Each...
متن کاملOutcome Evaluation of Therapeutic Community Model in Iran
Background Evaluation of treatment programs in addiction field is a prerequisite to improve the quality of care. This study aimed to investigate the effectiveness of Therapeutic Community (TC) program in Iran. Methods Individuals who had voluntarily enrolled in the TC center within a period of seven years, from early 2005 to late 2011, entered the study. Those who successfully completed the 1...
متن کامل