• DocumentCode
    1928166
  • Title

    A Risk Propagation Based Quantitative Assessment Methodology for Network Security - Aeronautical Network Case Study

  • Author

    Ben Mahmoud, Mohamed Slim ; Larrieu, Nicolas ; Pirovano, Alain

  • Author_Institution
    Commun., Navig., & Surveillance (CNS) Dept., Ecole Nat. de l´´Aviation Civile (ENAC), Toulouse, France
  • fYear
    2011
  • fDate
    18-21 May 2011
  • Firstpage
    1
  • Lastpage
    9
  • Abstract
    Recently, risk assessment has been considered as an essential technique in evaluating the security of network information systems. Many proposals have been made in this area in order to provide new approaches to allow administrators and engineers to analyze the impact of any attack that could target their systems. Nevertheless, there is a lack of quantitative techniques and methods which take into account the inherent characteristics of a network such as interconnection between nodes. This paper presents an original risk assessment approach based on risk propagation and network node correlation to provide relevant and accurate results. Each parameter involved in the risk assessment process is quantified then the overall approach is described in detail. At the end of the paper, the network security assessment methodology is applied to a satellite-based system architecture we designed for an industrial project entitled FAST (Fiber-like Aircraft Satellite Telecommunications). This project is co-funded by the Aerospace Valley pole and the French government (Direction Generale de la Competitivite, de l´Industrie et des Services - DGCIS, Fonds Unique Interministeriel - FUI) and aims to provide bi-directional satellite communication services on commercial aircraft worldwide.
  • Keywords
    computer network security; information systems; risk management; satellite communication; FAST; aeronautical network case study; bidirectional satellite communication service; fiber-like aircraft satellite telecommunication; network information systems; network security; quantitative assessment methodology; risk assessment approach; risk propagation; Databases; ISO standards; Information systems; Mathematical model; Risk management; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and Information Systems Security (SAR-SSI), 2011 Conference on
  • Conference_Location
    La Rochelle
  • Print_ISBN
    978-1-4577-0735-3
  • Type

    conf

  • DOI
    10.1109/SAR-SSI.2011.5931372
  • Filename
    5931372