Visible to the public A Framework for Measurability of Security

TitleA Framework for Measurability of Security
Publication TypeConference Paper
Year of Publication2017
AuthorsFayyad, S., Noll, J.
Conference Name2017 8th International Conference on Information and Communication Systems (ICICS)
ISBN Number978-1-5090-4243-2
KeywordsCommunication systems, computer network security, data privacy, Databases, embedded system, Embedded systems, Engines, ES, expert knowledge retrieval, expert systems, experts knowledge systematic storage, Human Behavior, Internet, Internet of Things, Measurement, MM framework, multi metrics, Multi-Metrics, privacy, privacy and dependability evaluation complexity, pubcrawl, resilience, Resiliency, Scalability, security, security attribute, security enhancement, security evaluation, security function, security measurability, security metric, SPD evaluation complexity, System analysis and design
Abstract

Having an effective security level for Embedded System (ES), helps a reliable and stable operation of this system. In order to identify, if the current security level for a given ES is effective or not, we need a proactive evaluation for this security level. The evaluation of the security level for ESs is not straightforward process, things like the heterogeneity among the components of ES complicate this process. One of the productive approaches, which overcame the complexity of evaluation for Security, Privacy and Dependability (SPD) is the Multi Metrics (MM). As most of SPD evaluation approaches, the MM approach bases on the experts knowledge for the basic evaluation. Regardless of its advantages, experts evaluation has some drawbacks, which foster the need for less experts-dependent evaluation. In this paper, we propose a framework for security measurability as a part of security, privacy and dependability evaluation. The security evaluation based on Multi Metric (MM) approach as being an effective approach for evaluations, thus, we call it MM framework. The art of evaluation investigated within MM framework, based also on systematic storing and retrieving of experts knowledge. Using MM framework, the administrator of the ES could evaluate and enhance the S-level of their system, without being an expert in security.

URLhttps://ieeexplore.ieee.org/document/7921989
DOI10.1109/IACS.2017.7921989
Citation Keyfayyad_framework_2017