{"title":"Bottom-up hierarchical real-time risk assessment for information system","authors":"Wan Li, Shengfeng Tian","doi":"10.1109/ICIST.2013.6747693","DOIUrl":null,"url":null,"abstract":"In this paper a bottom-up hierarchical real-time risk assessment approach based on risk propagation is presented. The approach calculates risks of services, hosts and network caused by attack processes in real-time. Risk index and risk status are used to quantify the risk situation. These two concepts are involved with three aspects of attacks: severity, certainty and successful possibility, and with the importance of the assets. Algorithms to calculate the risk index and risk status are proposed, and implementation is briefly introduced. Risk status decay is also proposed, which is important to adaptive response.","PeriodicalId":415759,"journal":{"name":"2013 IEEE Third International Conference on Information Science and Technology (ICIST)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-03-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 IEEE Third International Conference on Information Science and Technology (ICIST)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICIST.2013.6747693","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
In this paper a bottom-up hierarchical real-time risk assessment approach based on risk propagation is presented. The approach calculates risks of services, hosts and network caused by attack processes in real-time. Risk index and risk status are used to quantify the risk situation. These two concepts are involved with three aspects of attacks: severity, certainty and successful possibility, and with the importance of the assets. Algorithms to calculate the risk index and risk status are proposed, and implementation is briefly introduced. Risk status decay is also proposed, which is important to adaptive response.