Threat scenario-based security risk analysis using use case modeling in information systems

  • Kim, Young-Gab
  • Cha, Sungdeok
Citations

WEB OF SCIENCE

6
Citations

SCOPUS

18

초록

Successful Security Risk Analysis (SRA) enables us to develop a secure information management system and provides valuable analysis data for future risk estimation. One of the qualitative techniques for SRA is the scenario method. This provides a framework for our explorations that raises our awareness and appreciation of uncertainty. However, the existing scenario methods are too abstract to be applicable to some situations and have not been formalized in information systems (ISs) because they do not explicitly define artifacts or have any standard notation. Therefore, this paper proposes the improved scenario-based SRA approach, which can create SRA reports using threat scenario templates and manage security risk directly in ISs. Furthermore, in order to show how to apply the proposed method in a specific environment, especially in a Broadband convergence Network (BcN) environment, a case study is presented. Copyright (C) 2011 John Wiley & Sons, Ltd.

키워드

security risk analysisqualitative risk analysisscenario methoduse case modelingBroadband convergence Network (BcN)
제목
Threat scenario-based security risk analysis using use case modeling in information systems
저자
Kim, Young-GabCha, Sungdeok
DOI
10.1002/sec.321
발행일
2012-03
유형
Article
저널명
Security and Communication Networks
5
3
페이지
293 ~ 300