Security and Business Situational Awareness

被引:0
|
作者
Rieke, Roland [1 ,2 ]
Zhdanova, Maria [1 ]
Repp, Juergen [1 ]
机构
[1] Fraunhofer Inst SIT, Darmstadt, Germany
[2] Univ Marburg, Marburg, Germany
关键词
Predictive security analysis; Process behavior analysis; Security modeling and simulation; Security monitoring; Security strategy; Security information and event management; Governance and compliance; PERSPECTIVE; ENTERPRISE; FRAMEWORK; SYSTEMS;
D O I
10.1007/978-3-319-25360-2_9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
"Security needs to be aligned with business". Business situational awareness is the ability to continually monitor ongoing actions and events related to business operations and estimate the immediate and close-future impact of the new information. This ability is crucial for business continuity and should encompass all associated aspects. Considering the growing dependability of businesses on IT on the one hand, and ever increasing threats on the other, IT security aspects should get adequate attention in the awareness system. We present an approach to raise business situational awareness using an advanced method of predictive security analysis at runtime. It continually observes a system's event stream to find deviations from specified behavior and violations of security compliance rules. Operational models of the key processes are utilized to predict critical security states, evaluate possible countermeasures, and trigger corrective actions. A security information model maintains the security strategy and explains possible deviations from the originating goal. The approach is demonstrated on an industrial scenario from a European research project.
引用
收藏
页码:103 / 115
页数:13
相关论文
共 50 条
  • [21] Situational Awareness for Security Adaptation in Industrial Control Systems
    Evesti, Antti
    Frantti, Tapio
    2015 SEVENTH INTERNATIONAL CONFERENCE ON UBIQUITOUS AND FUTURE NETWORKS, 2015, : 1 - 6
  • [22] 'Situational awareness': Rethinking security in times of urban terrorism
    Krasmann, Susanne
    Hentschel, Christine
    SECURITY DIALOGUE, 2019, 50 (02) : 181 - 197
  • [23] The Classification, Design and Placement of Security Sensor for Network Security Situational Awareness System
    Wang Hui-qiang
    Lai Ji-bao
    Liang Ying
    Liu Xiao-wu
    ICICSE: 2008 INTERNATIONAL CONFERENCE ON INTERNET COMPUTING IN SCIENCE AND ENGINEERING, PROCEEDINGS, 2008, : 321 - 324
  • [24] Application of Cyber Situational Awareness and Cyber Security in Vehicular Networks
    Eiza, Mahmoud Hashem
    2017 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA), 2017,
  • [25] A novel stochastic modeling method for network security situational awareness
    Liang, Y.
    Wang, H. Q.
    Cai, H. B.
    He, Y. J.
    ICIEA 2008: 3RD IEEE CONFERENCE ON INDUSTRIAL ELECTRONICS AND APPLICATIONS, PROCEEDINGS, VOLS 1-3, 2008, : 2422 - +
  • [26] The Information System Security Situational Awareness Based On Cloud Computing
    Ma Zhicheng
    Jin Lin
    Yang Peng
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND SERVICE SYSTEM (CSSS), 2014, 109 : 583 - 586
  • [27] A Hierarchical Architectural Model for Network Security Exploring Situational Awareness
    Almeida, Ricardo Borges
    Covalski, Victor
    Machado, Roger
    Leal da Rosa, Diorgenes Yuri
    Yamin, Adenauer Correa
    Donato, Lucas Medeiros
    Pernas, Ana Marilza
    SAC '19: PROCEEDINGS OF THE 34TH ACM/SIGAPP SYMPOSIUM ON APPLIED COMPUTING, 2019, : 1365 - 1372
  • [28] Network video image processing for security, surveillance, and situational awareness
    Mahalanobis, A
    Cannon, J
    Stanfill, SR
    Muise, R
    Martin, L
    Shah, M
    DIGITAL WIRELESS COMMUNICATIONS VI, 2004, 5440 : 1 - 8
  • [29] Trusted network security situational awareness and forecast based on SPA
    Wu, Kun
    Bai, Zhong-Ying
    Harbin Gongye Daxue Xuebao/Journal of Harbin Institute of Technology, 2012, 44 (03): : 112 - 118
  • [30] Application of Cyber Situational Awareness and Cyber Security in Vehicular Networks
    Eiza, Mahmoud Hashem
    2017 INTERNATIONAL CONFERENCE ON CYBER SECURITY AND PROTECTION OF DIGITAL SERVICES (CYBER SECURITY), 2017,