Improving security decision under uncertainty: A multidisciplinary approach
Title | Improving security decision under uncertainty: A multidisciplinary approach |
Publication Type | Conference Paper |
Year of Publication | 2015 |
Authors | Dehghanniri, H., Letier, E., Borrion, H. |
Conference Name | 2015 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA) |
Date Published | June 2015 |
Publisher | IEEE |
ISBN Number | 978-0-9932-3380-7 |
Keywords | Companies, Credit cards, crime science, crime script, decision making, decision-making, identity theft, modelling language, pubcrawl170109, quantitative decision analysis, requirements engineering, risk, risk assessment, risk management, security, security decision-making, security of data, security risk, security threat, software engineering, Uncertainty |
Abstract | Security decision-making is a critical task in tackling security threats affecting a system or process. It often involves selecting a suitable resolution action to tackle an identified security risk. To support this selection process, decision-makers should be able to evaluate and compare available decision options. This article introduces a modelling language that can be used to represent the effects of resolution actions on the stakeholders' goals, the crime process, and the attacker. In order to reach this aim, we develop a multidisciplinary framework that combines existing knowledge from the fields of software engineering, crime science, risk assessment, and quantitative decision analysis. The framework is illustrated through an application to a case of identity theft. |
URL | https://ieeexplore.ieee.org/document/7166134 |
DOI | 10.1109/CyberSA.2015.7166134 |
Citation Key | dehghanniri_improving_2015 |
- requirements engineering
- uncertainty
- software engineering
- security threat
- security risk
- security of data
- security decision-making
- security
- risk management
- risk assessment
- Risk
- Companies
- quantitative decision analysis
- pubcrawl170109
- modelling language
- identity theft
- decision-making
- Decision Making
- crime script
- crime science
- Credit cards