当前位置: X-MOL 学术Int. J. Inf. Secur. › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
A risk-level assessment system based on the STRIDE/DREAD model for digital data marketplaces
International Journal of Information Security ( IF 3.2 ) Pub Date : 2021-09-14 , DOI: 10.1007/s10207-021-00566-3
Lu Zhang 1 , Arie Taal 1 , Reginald Cushing 1 , Paola Grosso 1 , Cees de Laat 2
Affiliation  

Security is a top concern in digital infrastructure and there is a basic need to assess the level of security ensured for any given application. To accommodate this requirement, we propose a new risk assessment system. Our system identifies threats of an application workflow, computes the severity weights with the modified Microsoft STRIDE/DREAD model and estimates the final risk exposure after applying security countermeasures in the available digital infrastructures. This allows potential customers to rank these infrastructures in terms of security for their own specific use cases. We additionally present a method to validate the stability and resolution of our ranking system with respect to subjective choices of the DREAD model threat rating parameters. Our results show that our system is stable against unavoidable subjective choices of the DREAD model parameters for a specific use case, with a rank correlation higher than 0.93 and normalised mean square error lower than 0.05.



中文翻译:

基于 STRIDE/DREAD 模型的数字数据市场风险级别评估系统

安全性是数字基础设施中的首要问题,并且基本需要评估为任何给定应用程序确保的安全级别。为了满足这一要求,我们提出了一个新的风险评估系统。我们的系统识别应用程序工作流的威胁,使用修改后的 Microsoft STRIDE/DREAD 模型计算严重性权重,并在可用的数字基础设施中应用安全对策后估计最终风险暴露。这允许潜在客户根据自己特定用例的安全性对这些基础设施进行排名。我们还提出了一种方法来验证我们的排名系统在 DREAD 模型威胁评级参数的主观选择方面的稳定性和分辨率。

更新日期:2021-09-15
down
wechat
bug