自动化和按需网络安全认证

Stylianos Karagiannis, Marco Manso, E. Magkos, Luís L. Ribeiro, Luís Campos
{"title":"自动化和按需网络安全认证","authors":"Stylianos Karagiannis, Marco Manso, E. Magkos, Luís L. Ribeiro, Luís Campos","doi":"10.1109/CSR51186.2021.9527958","DOIUrl":null,"url":null,"abstract":"The digital world nowadays consists of a very high number of devices and software services that are being used and constantly exposed to the Internet. Furthermore, with the evolution of the Internet of Things (IoT), the cybersecurity threat landscape has overall increased. Consequently, various certification frameworks have been developed for maintaining the overall security posture and supporting the required security tests. This paper describes an approach for conducting automated and on-demand cybersecurity certification on systems and software components. Taking the existing cybersecurity frameworks and guidelines into consideration, the developed software/service component aims to provide auditing information and insights from the systems-on-the-test, to certify newly entering components that could increase the security risk. The recommended approach can be used for collecting, extracting, and generating reports regarding the security aspects of the submitted digital assets by deploying automated security tests and auditing processes that will contribute to the certification process.","PeriodicalId":253300,"journal":{"name":"2021 IEEE International Conference on Cyber Security and Resilience (CSR)","volume":"35 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-07-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Automated and On-Demand Cybersecurity Certification\",\"authors\":\"Stylianos Karagiannis, Marco Manso, E. Magkos, Luís L. Ribeiro, Luís Campos\",\"doi\":\"10.1109/CSR51186.2021.9527958\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The digital world nowadays consists of a very high number of devices and software services that are being used and constantly exposed to the Internet. Furthermore, with the evolution of the Internet of Things (IoT), the cybersecurity threat landscape has overall increased. Consequently, various certification frameworks have been developed for maintaining the overall security posture and supporting the required security tests. This paper describes an approach for conducting automated and on-demand cybersecurity certification on systems and software components. Taking the existing cybersecurity frameworks and guidelines into consideration, the developed software/service component aims to provide auditing information and insights from the systems-on-the-test, to certify newly entering components that could increase the security risk. The recommended approach can be used for collecting, extracting, and generating reports regarding the security aspects of the submitted digital assets by deploying automated security tests and auditing processes that will contribute to the certification process.\",\"PeriodicalId\":253300,\"journal\":{\"name\":\"2021 IEEE International Conference on Cyber Security and Resilience (CSR)\",\"volume\":\"35 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-07-26\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2021 IEEE International Conference on Cyber Security and Resilience (CSR)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/CSR51186.2021.9527958\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE International Conference on Cyber Security and Resilience (CSR)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CSR51186.2021.9527958","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

如今的数字世界由大量的设备和软件服务组成,这些设备和软件服务正在被使用并不断暴露在互联网上。此外,随着物联网(IoT)的发展,网络安全威胁形势总体上有所增加。因此,已经开发了各种认证框架来维护整体安全状态并支持所需的安全测试。本文描述了一种对系统和软件组件进行自动化和按需网络安全认证的方法。考虑到现有的网络安全框架和指导方针,开发的软件/服务组件旨在提供来自测试系统的审计信息和见解,以认证可能增加安全风险的新进入组件。推荐的方法可用于通过部署有助于认证流程的自动化安全测试和审计流程来收集、提取和生成关于提交的数字资产的安全方面的报告。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Automated and On-Demand Cybersecurity Certification
The digital world nowadays consists of a very high number of devices and software services that are being used and constantly exposed to the Internet. Furthermore, with the evolution of the Internet of Things (IoT), the cybersecurity threat landscape has overall increased. Consequently, various certification frameworks have been developed for maintaining the overall security posture and supporting the required security tests. This paper describes an approach for conducting automated and on-demand cybersecurity certification on systems and software components. Taking the existing cybersecurity frameworks and guidelines into consideration, the developed software/service component aims to provide auditing information and insights from the systems-on-the-test, to certify newly entering components that could increase the security risk. The recommended approach can be used for collecting, extracting, and generating reports regarding the security aspects of the submitted digital assets by deploying automated security tests and auditing processes that will contribute to the certification process.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信