An experimental evaluation of bow-tie analysis for security

被引:5
|
作者
Meland P.H. [1 ,2 ]
Bernsmed K. [1 ]
Frøystad C. [1 ]
Li J. [2 ]
Sindre G. [2 ]
机构
[1] Department of Digital, SINTEF for Industriell og Teknisk Forskning, Trondheim
[2] Department of Computer Science, Norwegian University of Science and Technology, Trondheim
关键词
Bow-tie analysis; Controlled experiment; Misuse case; Security; Threats;
D O I
10.1108/ICS-11-2018-0132
中图分类号
学科分类号
摘要
Purpose: Within critical-infrastructure industries, bow-tie analysis is an established way of eliciting requirements for safety and reliability concerns. Because of the ever-increasing digitalisation and coupling between the cyber and physical world, security has become an additional concern in these industries. The purpose of this paper is to evaluate how well bow-tie analysis performs in the context of security, and the study’s hypothesis is that the bow-tie notation has a suitable expressiveness for security and safety. Design/methodology/approach: This study uses a formal, controlled quasi-experiment on two sample populations – security experts and security graduate students – working on the same case. As a basis for comparison, the authors used a similar experiment with misuse case analysis, a well-known technique for graphical security modelling. Findings: The results show that the collective group of graduate students, inexperienced in security modelling, perform similarly as security experts in a well-defined scope and familiar target system/situation. The students showed great creativity, covering most of the same threats and consequences as the experts identified and discovering additional ones. One notable difference was that these naïve professionals tend to focus on preventive barriers, leading to requirements for risk mitigation or avoidance, while experienced professionals seem to balance this more with reactive barriers and requirements for incident management. Originality/value: Our results are useful in areas where we need to evaluate safety and security concerns together, especially for domains that have experience in health, safety and environmental hazards, but now need to expand this with cybersecurity as well. © 2019, Per Håkon Meland, Karin Bernsmed, Christian Frøystad, Jingyue Li and Guttorm Sindre.
引用
收藏
页码:536 / 561
页数:25
相关论文
共 50 条
  • [31] Local bow-tie structure of the web
    Yuji Fujita
    Yuichi Kichikawa
    Yoshi Fujiwara
    Wataru Souma
    Hiroshi Iyetomi
    Applied Network Science, 4
  • [32] Spectral Tuning of a Folded Bow-tie Antenna
    Lail, Brian A.
    Mullin, Scott
    2010 IEEE ANTENNAS AND PROPAGATION SOCIETY INTERNATIONAL SYMPOSIUM, 2010,
  • [33] Composite bow-tie nano-antenna
    Morshed, Monir
    Khaleque, Abdul
    Hattori, Haroldo T.
    2017 CONFERENCE ON LASERS AND ELECTRO-OPTICS PACIFIC RIM (CLEO-PR), 2017,
  • [34] OPTIMIZATION OF BOW-TIE ANTENNAS FOR PULSE RADIATION
    SHLAGER, KL
    SMITH, GS
    MALONEY, JG
    IEEE TRANSACTIONS ON ANTENNAS AND PROPAGATION, 1994, 42 (07) : 975 - 982
  • [35] Frequency reconfigurable bow-tie antenna array
    Li, Tong
    Zhai, Huiqing
    Liang, Chang-Hong
    ELECTRONICS LETTERS, 2014, 50 (18) : 1264 - 1265
  • [36] Flexible Bow-Tie Antennas with Reduced Metallization
    Durgun, Ahmet C.
    Reese, Mark S.
    Balanis, Constantine A.
    Birtcher, Craig R.
    Allee, David R.
    Venugopal, Sameer
    2011 IEEE RADIO AND WIRELESS SYMPOSIUM (RWS), 2011, : 50 - 53
  • [37] Plane wave scattering by bow-tie posts
    Lech, R
    Mazur, J
    MICROWAVE AND OPTICAL TECHNOLOGY 2003, 2003, 5445 : 244 - 247
  • [38] Development of Scented Bow-Tie: User Experience
    Elesini, Ursa Stankovic
    Svarc, Jernej
    Sumiga, Bostjan
    Urbas, Rasa
    TEKSTILEC, 2016, 59 (03) : 206 - 215
  • [39] Radiation Characteristics of a Flexible Bow-tie Antenna
    Durgun, Ahmet C.
    Balanis, Constantine A.
    Birtcher, Craig R.
    Allee, David R.
    2011 IEEE INTERNATIONAL SYMPOSIUM ON ANTENNAS AND PROPAGATION (APSURSI), 2011, : 1239 - 1242
  • [40] Study of Folded Bow-tie Antenna with a Reflector
    Abiru, Jun
    Michishita, Naobumi
    Morishita, Hisashi
    Kawabata, Kenji
    Murakami, Yasuhiro
    2018 INTERNATIONAL SYMPOSIUM ON ANTENNAS AND PROPAGATION (ISAP), 2018,