The Experts below are selected from a list of 2280 Experts worldwide ranked by ideXlab platform

Raimundas Matulevičius - One of the best experts on this subject based on the ideXlab platform.

  • OTM Conferences - Security Risk Management in Cooperative Intelligent Transportation Systems: A Systematic Literature Review
    Lecture Notes in Computer Science, 2019
    Co-Authors: Abasi-amefon O. Affia, Raimundas Matulevičius, Alexander Nolte
    Abstract:

    The automotive industry is maximizing cooperative interactions between vehicular sensors and infrastructure components to make intelligent decisions in its application (i.e., traffic Management, navigation, or autonomous driving services). This cooperative behaviour also extends to Security. More connected and cooperative components of vehicular intelligent transportation systems (ITS) result in an increased potential for malicious attacks that can negatively impact Security and safety. The Security Risks in one architecture layer affect other layers of ITS; thus, cooperation is essential for secure operations of these systems. This paper presents results from a comprehensive literature review on the state-of-the-art of Security Risk Management in vehicular ITS, evaluating its assets, threats/Risks, and countermeasures. We examine these Security elements along the dimensions of the perception, network, and application architecture layers of ITS. The study reveals gaps in ITS Security Risk Management research within these architecture layers and provides suggestions for future research.

  • Assessment of Aviation Security Risk Management for Airline Turnaround Processes
    Transactions on Large-Scale Data- and Knowledge-Centered Systems XXXVI, 2017
    Co-Authors: Raimundas Matulevičius, Alex Norta, Chibozur Udokwu, Rein Nõukas
    Abstract:

    Security in the aircraft business attracts heightened attention because of the expansion of differing cyber attacks, many being driven by technology innovation. Continuous research does not consider the sociotechnical essence of Security in basic areas, for example, carrier turnaround systems. To cut time and costs, the latter comprises several companies for ticket- and luggage Management, maintenance checks, cleaning, passenger transportation, re-fueling, and so on. The carrier business has embraced broadly data innovation for guaranteeing that aircrafts are in a state to take off again as fast as would be prudent. Progressively, this prompts the development of a virtual enterprise that utilizes data advances to consistently coordinate individual airline-turnaround processes into a single structure. The subsequent sociotechnical Security Risk Management issues are not clearly understood and require further examination. This paper fills the gap with an assessment about the application of a Security Risk Management strategy to identify business assets for a more profound Risk mitigation analyses. The result of this paper provides knowledge about the usefulness of existing Security Risk Management approaches.

  • Mal-activities for Security Risk Management
    Fundamentals of Secure System Modelling, 2017
    Co-Authors: Raimundas Matulevičius
    Abstract:

    In this chapter, on Mal-activities for Security Risk Management, introduces Security Risk Management extensions to mal-activity diagrams, another languages of the UML family. The chapter illustrates how to analyse dynamic aspects of secure software system development.

  • Domain Model for Information Systems Security Risk Management
    Fundamentals of Secure System Modelling, 2017
    Co-Authors: Raimundas Matulevičius
    Abstract:

    In this chapter, on Domain Model for Information Systems Security Risk Management, we discuss the ISSRM domain model, including definitions of asset-related, Security Risk-related, and Security Risk treatment-related concepts. This chapter also discusses concept relationships, multiplicities, processes as well as the metrics used to assess Security Risks.

  • FDSE - Security Risk Management in the Aviation Turnaround Sector
    Future Data and Security Engineering, 2016
    Co-Authors: Raimundas Matulevičius, Alex Norta, Chibozur Udokwu, Rein Nõukas
    Abstract:

    Security in the airline industry receives heightened attention due to an increase of diverse attacks, many being driven by information technology. Ongoing research does not take into account the sociotechnical nature of Security in critical domains such as airline turnaround systems. To cut time and costs, the latter comprises several companies for ticket- and luggage Management, maintenance checks, cleaning, passenger transportation, re-fueling, and so on. The airline industry has adopted extensively information technology for assuring an incoming airplane is in a state to take off again as quickly as possible. Increasingly, this leads to the emergence of a virtual enterprise that uses information technologies to seamlessly integrate respective airline-turnaround processes into one composition. The resulting sociotechnical Security Risk Management issues are not well understood and require diligent investigation. This paper fills the gap with an evaluation about the application of a Security Risk Management method to identify critical business- and information-technology assets for a deeper Risk mitigation analysis. The results of this paper yield insights about the utility of existing Security Risk Management approach.

Metin Cakanyildirim - One of the best experts on this subject based on the ideXlab platform.

  • network externalities layered protection and it Security Risk Management
    Decision Support Systems, 2007
    Co-Authors: Metin Cakanyildirim
    Abstract:

    This paper considers two important issues related to Security Risk Management. First, the presence of network externalities in Security Risks. Second, the distinction of general (network) and system-specific protection measures. We found the optimal allocation of Security resources (investments) in protecting every system in an organization. The results show that the consideration of network externalities and layered protection changes the Risk mitigation decisions significantly. In addition, accurate estimation of system Risk plays a critical role in the success of Risk Management. Otherwise, the use of a uniform baseline protection approach may be more desirable when the misjudgment of relative system Risks is likely to occur.

  • Network externalities, layered protection and IT Security Risk Management
    Decision Support Systems, 2007
    Co-Authors: Wei T. Yue, Young U. Ryu, Metin Cakanyildirim, D. Liu
    Abstract:

    This paper considers two important issues related to Security Risk Management. First, the presence of network externalities in Security Risks. Second, the distinction of general (network) and system-specific protection measures. We found the optimal allocation of Security resources (investments) in protecting every system in an organization. The results show that the consideration of network externalities and layered protection changes the Risk mitigation decisions significantly. In addition, accurate estimation of system Risk plays a critical role in the success of Risk Management. Otherwise, the use of a uniform baseline protection approach may be more desirable when the misjudgment of relative system Risks is likely to occur. © 2006 Elsevier B.V. All rights reserved.

Patrick Heymans - One of the best experts on this subject based on the ideXlab platform.

  • syntactic and semantic extensions to secure tropos to support Security Risk Management
    Journal of Universal Computer Science, 2012
    Co-Authors: Raimundas Matulevičius, Haralambos Mouratidis, Mayer Nicolas, Dubois Eric, Patrick Heymans
    Abstract:

    The need to consider Security from the early stages of the development pro- cess of information systems has been argued by academics and industrialists alike, and Security Risk Management has been recognised as one of the most prominent techniques for eliciting Security requirements. However, although existing Security modelling lan- guages provide some means to model Security aspects, they do not contain concrete constructs to address vulnerable system assets, their Risks, and Risk treatments. Fur- thermore, Security languages do not provide a crosscutting viewpoint relating all three - assets, Risks and Risk treatments - together. This is problematic since, for a Security analyst, it is difficult to detect what the potential Security flaws could be, and how they need to be fixed. In this paper, we extend the Secure Tropos language, an agent- and goal-oriented Security modelling language to support modelling of Security Risks. Based on previous work, where we had observed some inadequacies of this language to model Security Risks, this paper suggests improvements of Secure Tropos semantics and syntax. On the syntax level we extend the concrete and abstract syntax of the lan- guage, so that it covers the Security Risk Management domain. On the semantic level, we illustrate how language constructs need to be improved to address the three dif- ferent levels of Security Risk Management. The suggested improvements are illustrated with the aid of a running example, called eSAP, from the healthcare domain.

  • Intentional Perspectives on Information Systems Engineering - A Systematic Approach to Define the Domain of Information System Security Risk Management
    Intentional Perspectives on Information Systems Engineering, 2010
    Co-Authors: Eric Dubois, Patrick Heymans, Nicolas Mayer, Raimundas Matulevičius
    Abstract:

    Today, Security concerns are at the heart of information systems, both at technological and organizational levels. With over 200 practitioner-oriented Risk Management methods and several academic Security modelling frameworks available, a major challenge is to select the most suitable approach. Choice is made even more difficult by the absence of a real understanding of the Security Risk Management domain and its ontology of related concepts. This chapter contributes to the emergence of such an ontology. It proposes and applies a rigorous approach to build an ontology, or domain model, of information system Security Risk Management. The proposed domain model can then be used to compare, select or otherwise improve Security Risk Management methods.

  • a systematic approach to define the domain of information system Security Risk Management
    Intentional Perspectives on Information Systems Engineering, 2010
    Co-Authors: Eric Dubois, Patrick Heymans, Nicolas Mayer, Raimundas Matulevičius
    Abstract:

    Today, Security concerns are at the heart of information systems, both at technological and organizational levels. With over 200 practitioner-oriented Risk Management methods and several academic Security modelling frameworks available, a major challenge is to select the most suitable approach. Choice is made even more difficult by the absence of a real understanding of the Security Risk Management domain and its ontology of related concepts. This chapter contributes to the emergence of such an ontology. It proposes and applies a rigorous approach to build an ontology, or domain model, of information system Security Risk Management. The proposed domain model can then be used to compare, select or otherwise improve Security Risk Management methods.

  • Alignment of Misuse Cases with Security Risk Management
    2008 Third International Conference on Availability Reliability and Security, 2008
    Co-Authors: Raimundas Matulevičius, Nicolas Mayer, Patrick Heymans
    Abstract:

    It is recognised that Security has to be addressed through the whole system development process. However current practices address Security only in late stages, i.e., development or maintenance. Due to the success of UML use cases, misuse cases have been accepted by industry as a means to tackle Security. However misuse cases, firstly, lack a precise application process, secondly, are too general which results in under-definition or misinterpretation of their concepts. In this paper we examine misuse cases in the light of a reference model for information system Security Risk Management (ISSRM). Using the well-known meeting scheduler example we show how misuse cases can be used to follow a Security Risk Management process. Next we check the misuse case ontology according to the concepts found in current Risk Management standards. The paper suggests improvements for the conceptual appropriateness of misuse cases for the Security Risk domain.

  • ARES - Alignment of Misuse Cases with Security Risk Management
    2008 Third International Conference on Availability Reliability and Security, 2008
    Co-Authors: Raimundas Matulevičius, Nicolas Mayer, Patrick Heymans
    Abstract:

    It is recognised that Security has to be addressed through the whole system development process. However current practices address Security only in late stages, i.e., development or maintenance. Due to the success of UML use cases, misuse cases have been accepted by industry as a means to tackle Security. However misuse cases, firstly, lack a precise application process, secondly, are too general which results in under-definition or misinterpretation of their concepts. In this paper we examine misuse cases in the light of a reference model for information system Security Risk Management (ISSRM). Using the well-known meeting scheduler example we show how misuse cases can be used to follow a Security Risk Management process. Next we check the misuse case ontology according to the concepts found in current Risk Management standards. The paper suggests improvements for the conceptual appropriateness of misuse cases for the Security Risk domain.

D. Liu - One of the best experts on this subject based on the ideXlab platform.

  • Network externalities, layered protection and IT Security Risk Management
    Decision Support Systems, 2007
    Co-Authors: Wei T. Yue, Young U. Ryu, Metin Cakanyildirim, D. Liu
    Abstract:

    This paper considers two important issues related to Security Risk Management. First, the presence of network externalities in Security Risks. Second, the distinction of general (network) and system-specific protection measures. We found the optimal allocation of Security resources (investments) in protecting every system in an organization. The results show that the consideration of network externalities and layered protection changes the Risk mitigation decisions significantly. In addition, accurate estimation of system Risk plays a critical role in the success of Risk Management. Otherwise, the use of a uniform baseline protection approach may be more desirable when the misjudgment of relative system Risks is likely to occur. © 2006 Elsevier B.V. All rights reserved.

Wei T. Yue - One of the best experts on this subject based on the ideXlab platform.

  • Network externalities, layered protection and IT Security Risk Management
    Decision Support Systems, 2007
    Co-Authors: Wei T. Yue, Young U. Ryu, Metin Cakanyildirim, D. Liu
    Abstract:

    This paper considers two important issues related to Security Risk Management. First, the presence of network externalities in Security Risks. Second, the distinction of general (network) and system-specific protection measures. We found the optimal allocation of Security resources (investments) in protecting every system in an organization. The results show that the consideration of network externalities and layered protection changes the Risk mitigation decisions significantly. In addition, accurate estimation of system Risk plays a critical role in the success of Risk Management. Otherwise, the use of a uniform baseline protection approach may be more desirable when the misjudgment of relative system Risks is likely to occur. © 2006 Elsevier B.V. All rights reserved.