DocumentCode
1928166
Title
A Risk Propagation Based Quantitative Assessment Methodology for Network Security - Aeronautical Network Case Study
Author
Ben Mahmoud, Mohamed Slim ; Larrieu, Nicolas ; Pirovano, Alain
Author_Institution
Commun., Navig., & Surveillance (CNS) Dept., Ecole Nat. de l´´Aviation Civile (ENAC), Toulouse, France
fYear
2011
fDate
18-21 May 2011
Firstpage
1
Lastpage
9
Abstract
Recently, risk assessment has been considered as an essential technique in evaluating the security of network information systems. Many proposals have been made in this area in order to provide new approaches to allow administrators and engineers to analyze the impact of any attack that could target their systems. Nevertheless, there is a lack of quantitative techniques and methods which take into account the inherent characteristics of a network such as interconnection between nodes. This paper presents an original risk assessment approach based on risk propagation and network node correlation to provide relevant and accurate results. Each parameter involved in the risk assessment process is quantified then the overall approach is described in detail. At the end of the paper, the network security assessment methodology is applied to a satellite-based system architecture we designed for an industrial project entitled FAST (Fiber-like Aircraft Satellite Telecommunications). This project is co-funded by the Aerospace Valley pole and the French government (Direction Generale de la Competitivite, de l´Industrie et des Services - DGCIS, Fonds Unique Interministeriel - FUI) and aims to provide bi-directional satellite communication services on commercial aircraft worldwide.
Keywords
computer network security; information systems; risk management; satellite communication; FAST; aeronautical network case study; bidirectional satellite communication service; fiber-like aircraft satellite telecommunication; network information systems; network security; quantitative assessment methodology; risk assessment approach; risk propagation; Databases; ISO standards; Information systems; Mathematical model; Risk management; Security;
fLanguage
English
Publisher
ieee
Conference_Titel
Network and Information Systems Security (SAR-SSI), 2011 Conference on
Conference_Location
La Rochelle
Print_ISBN
978-1-4577-0735-3
Type
conf
DOI
10.1109/SAR-SSI.2011.5931372
Filename
5931372
Link To Document