A. Hapon, V. Fedorchenko, V. Martovytskyi, Volodymyr Rykun, Oleksandr Sievierinov, I. Oleshko
{"title":"Measuring Vulnerabilities in Threat Modelling with Risk Matrix","authors":"A. Hapon, V. Fedorchenko, V. Martovytskyi, Volodymyr Rykun, Oleksandr Sievierinov, I. Oleshko","doi":"10.1109/PICST54195.2021.9772211","DOIUrl":null,"url":null,"abstract":"Threat modeling is one of the most important parts when it comes to security in development of programing product. The main challenges for that are time and prioritization of the scope of work. Risk matrix is effective tool for making clear what should be done first and which consequences can be. There are few levels of consequences which are ranged by the influence on business. With help of vul-nerability assessment threats can be measured by impact on confidentiality, in-tegrity, and availability. The Common Vulnerability Scoring System is appropri-ate tool for catching the principal characteristics of a vulnerability and produce numerical score reflecting its severity.","PeriodicalId":391592,"journal":{"name":"2021 IEEE 8th International Conference on Problems of Infocommunications, Science and Technology (PIC S&T)","volume":"39 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-10-05","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE 8th International Conference on Problems of Infocommunications, Science and Technology (PIC S&T)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/PICST54195.2021.9772211","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Threat modeling is one of the most important parts when it comes to security in development of programing product. The main challenges for that are time and prioritization of the scope of work. Risk matrix is effective tool for making clear what should be done first and which consequences can be. There are few levels of consequences which are ranged by the influence on business. With help of vul-nerability assessment threats can be measured by impact on confidentiality, in-tegrity, and availability. The Common Vulnerability Scoring System is appropri-ate tool for catching the principal characteristics of a vulnerability and produce numerical score reflecting its severity.