DocumentCode
2284083
Title
Applying a model of configuration complexity to measure security impact on IT procedures
Author
Moura, Giovane Cesar Moreira ; Gaspary, Luciano Paschoal
Author_Institution
Inst. of Inf., Fed. Univ. of Rio Grande do Sul, Porto Alegre
fYear
2008
fDate
7-11 April 2008
Firstpage
97
Lastpage
104
Abstract
IT security has become over the recent years a major concern for organizations. However, it doesn´t come without large investments on both the acquisition of tools to satisfy particular security requirements and complex procedures to deploy and maintain a protected infrastructure. The scientific community has proposed in the recent past models and techniques to measure the complexity of configuration procedures, aware that they represent a significant operational cost, often dominating total cost of ownership. However, despite the central role played by security within this context, it has not been subject to any investigation so far. To address this issue, we apply a model of configuration complexity proposed in the literature in order to be able to estimate security impact on the complexity of IT procedures. Our proposal has been materialized through a prototypical implementation of a complexity scorer system called security complexity analyzer (SCA). To prove concept and technical feasibility of our proposal, we have used the SCA to evaluate real-life security scenarios.
Keywords
security of data; IT security; configuration complexity model; security complexity analyzer; Authentication; Automation; Costs; Data security; Hardware; Informatics; Information security; Proposals; Protection; Prototypes;
fLanguage
English
Publisher
ieee
Conference_Titel
Network Operations and Management Symposium, 2008. NOMS 2008. IEEE
Conference_Location
Salvador, Bahia
ISSN
1542-1201
Print_ISBN
978-1-4244-2065-0
Electronic_ISBN
1542-1201
Type
conf
DOI
10.1109/NOMS.2008.4575122
Filename
4575122
Link To Document