DocumentCode :
3506676
Title :
A framework for security metrics based on operational system attributes
Author :
Jonsson, E. ; Pirzadeh, L.
Author_Institution :
Dept. of Comput. Sci. & Eng., Chalmers Univ. of Technol., Goteborg, Sweden
fYear :
2011
fDate :
21-21 Sept. 2011
Firstpage :
58
Lastpage :
65
Abstract :
There exists a large number of suggestions for how to measure security, with different goals and objectives. The application areas range from business management and organizational systems to large software systems. The approaches may be theoretical, technical, administrative or practical. In many cases the goal is to find a single overall metric of security. Given that security is a complex and multi-faceted property, we believe that there are fundamental problems to find such an overall metric. Thus, we suggest a framework for security metrics that is based on a number of system attributes taken from the security and the dependability disciplines. We start out from the traditional decomposition of security into three main aspects ("CIA") and include a set of dependability attributes. The reason for this is that security and dependability largely reflect the same basic system feature and are partly overlapping. We then regroup those attributes according to an existing conceptual system model and propose metrication methods in accordance. We suggest that there should be metrics related to protective attributes, to behavioural attributes and to system correctness. We also discuss the relation between these types of metrics. We are convinced that this approach will facilitate making quantitative assessment of the concept of combined security and dependability and that it would also improve our understanding of these important system properties.
Keywords :
organisational aspects; security of data; software metrics; behavioural attributes; business management; conceptual system model; dependability attributes; metrication methods; operational system attributes; organizational systems; quantitative assessment; security metrics; software systems; Availability; Conferences; Measurement; NIST; Safety; Security; behavioural metrics; effort-based metrics; modelling; operational security; security metrics;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Security Measurements and Metrics (Metrisec), 2011 Third International Workshop on
Conference_Location :
Banff, AB
Print_ISBN :
978-1-4673-1245-5
Type :
conf
DOI :
10.1109/Metrisec.2011.19
Filename :
6165764
Link To Document :
بازگشت