The layered security model: Analysis of systems from the conceptual, logical and physical viewpoints

被引:0
|
作者
Blackwell, Clive [1 ]
机构
[1] Univ London, Informat Secur Grp, Egham, Surrey, England
关键词
security model; architecture; fraud; financial transaction;
D O I
暂无
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Most security models are only suitable for limited problem domains, and are incomplete, as they do not consider all the ways security issues can arise. We have developed a practical security model that can be used to analyse systems more systematically, match more faithfully to their requirements, and which has widespread application. The model has three layers, which are the semantic (involving people), logical (computers) and physical layers including the relationships and interactions between them. This allows the analysis of systems in their entirety including human and physical factors, not just as technical systems. The model also has a horizontal constituent to represent the separate conceptual scope and connectivity of systems and entities at different layers. The model is intended to help in analysing, designing and configuring systems that can possibly be compromised at all three layers. It has application to broad problem domains such as critical infrastructure protection and specific business contexts such as banking applications. In addition, it can be used on a smaller scale to analyse components of systems or to investigate specific vulnerabilities. We examine the system of credit card transactions on the Internet to demonstrate the benefits of the model.
引用
收藏
页码:27 / 36
页数:10
相关论文
共 50 条
  • [1] PHYSICAL AND LOGICAL SECURITY RISK ANALYSIS MODEL
    Pecina, Koldo
    Bilbao, Alfonso
    Bilbao, Enrique
    2011 IEEE INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2011,
  • [2] Transforming Conceptual Model into Logical Model for Temporal Data Warehouse Security: A Case Study
    Farhan, Marwa S.
    Marie, Mohamed E.
    El-Fangary, Laila M.
    Helmy, Yehia K.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2012, 3 (03) : 115 - 122
  • [3] A Physical and Logical Security Framework for Multilevel AFCI Systems in Smart Grid
    Kim, Seong-Woo
    Lee, Eun-Dong
    Je, Dong-Hyun
    Seo, Seung-Woo
    IEEE TRANSACTIONS ON SMART GRID, 2011, 2 (03) : 496 - 506
  • [4] Conceptual model of the physical structure of manufacturing systems
    Noureddine, Myriam
    INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING, 2006, 16 (04) : 643 - 651
  • [5] ACTEN: A CONCEPTUAL MODEL FOR SECURITY SYSTEMS DESIGN.
    Fugini, Mariagrazia
    Martella, Giancarlo
    1600, (03):
  • [6] Hierarchies in a multidimensional model:: From conceptual modeling to logical representation
    Malinowski, E.
    Zimanyi, E.
    DATA & KNOWLEDGE ENGINEERING, 2006, 59 (02) : 348 - 377
  • [7] A conceptual layered cooperative system of systems model for smart grid
    Huazhong University of Science and Technology, Wuhan 430074, China
    Dianli Xitong Zidonghue, 2009, 17 (6-9+104):
  • [8] Constructing Conceptual Model for Security Culture in Health Information Systems Security Effectiveness
    Shahri, Ahmad Bakhtiyari
    Ismail, Zuraini
    Ab Rahim, Nor Zairah
    ADVANCES IN INFORMATION SYSTEMS AND TECHNOLOGIES, 2013, 206 : 213 - 220
  • [9] Security analysis and design based on a general conceptual security model and UML
    Blobel, B
    Pharow, P
    Roger-France, F
    HIGH-PERFORMANCE COMPUTING AND NETWORKING, PROCEEDINGS, 1999, 1593 : 919 - 930
  • [10] A Conceptual Model Approach to Manage and Audit Information Systems Security
    Pereira, Teresa
    Santos, Henrique
    PROCEEDINGS OF THE 9TH EUROPEAN CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2010, : 360 - 365