PRISM: A preventive and risk-reducing integrated security management model using security label

被引:0
|
作者
D. S. Kim
Y. J. Jung
T. M. Chung
机构
[1] Sungkyunkwan Univ.,School of Information and Communication Engineering
[2] National Security Research Institute (NSRI),undefined
[3] School of Information and Communication Engineering,undefined
[4] Sungkyunkwan Univ.,undefined
关键词
security management; security label; ESM; ISM;
D O I
10.1007/BF02764144
中图分类号
学科分类号
摘要
An automated security management integrating various security systems is strongly required because cyber attacks are evolving day after day. Moreover, the attacks are become more complex and intelligent than past. Several integrated security management (ISM) models are supposed and implemented to meet the requirements. However, the current ISM is passive and behaves in a post-event manner. To reduce costs and resources for managing security and to remove the possibility of an intruder succeeding in attacks, the preventive security management technology is strongly required. This paper proposes the PRISM model that is based on tracing important assets in a managed network and performs preventive security management before security incidents occur. Additionally, PRISM model employs security labels to deploy differentiated security measure. The PRISM will provide concrete and effective security management to the organization’s network.
引用
收藏
页码:103 / 121
页数:18
相关论文
共 50 条
  • [11] Security Risk Management Using Incentives
    Liu, Debin
    Li, Ninghui
    Wang, XiaoFeng
    Camp, L. Jean
    IEEE SECURITY & PRIVACY, 2011, 9 (06) : 20 - 28
  • [12] Integrated management pattern of marine security synthesis risk
    Wang Yue
    Ren Xue-Hui
    Ding Yong-Sheng
    Yu Chang-Ying
    APPLIED ARTIFICIAL INTELLIGENCE, 2006, : 665 - +
  • [13] An integrated conceptual model for information system security risk management supported by enterprise architecture management
    Mayer, Nicolas
    Aubert, Jocelyn
    Grandry, Eric
    Feltus, Christophe
    Goettelmann, Elio
    Wieringa, Roel
    SOFTWARE AND SYSTEMS MODELING, 2019, 18 (03): : 2285 - 2312
  • [14] An integrated conceptual model for information system security risk management supported by enterprise architecture management
    Nicolas Mayer
    Jocelyn Aubert
    Eric Grandry
    Christophe Feltus
    Elio Goettelmann
    Roel Wieringa
    Software & Systems Modeling, 2019, 18 : 2285 - 2312
  • [15] Information security risk assessment model for risk management
    Wawrzyniak, Dariusz
    TRUST, PRIVACY, AND SECURITY IN DIGITAL BUSINESS, PROCEEDINGS, 2006, 4083 : 21 - 30
  • [16] Integrated Model of Security Policy in Database Management System
    Boichenko, I. A.
    Sarajkin, V. G.
    LESNOY ZHURNAL-FORESTRY JOURNAL, 2005, (05) : 133 - +
  • [17] The game model for reducing the security risk of Chinese commercial bank
    Qiao, Li-Xin
    Yuan, Ai-Ling
    Li, Shu-Xia
    Feng, Ying-Jun
    Xitong Gongcheng Lilun yu Shijian/System Engineering Theory and Practice, 2006, 26 (09): : 43 - 50
  • [18] Integrated Management of Security Policies
    Paraboschi, Stefano
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXV, 2011, 6818 : 12 - 13
  • [19] An Integrated Conceptual Model for Information System Security Risk Management and Enterprise Architecture Management Based on TOGAF
    Mayer, Nicolas
    Aubert, Jocelyn
    Grandry, Eric
    Feltus, Christophe
    PRACTICE OF ENTERPRISE MODELING, POEM 2016, 2016, 267 : 353 - 361
  • [20] Integrated risk assessment and security
    Mahutova, K
    Barich, JJ
    CHEMISTRY FOR THE PROTECTION OF THE ENVIRONMENT 4, 2005, 59 : 177 - 182