完整後設資料紀錄
DC 欄位語言
dc.contributor.authorWang, Pingen_US
dc.contributor.authorChao, Kuo-Mingen_US
dc.contributor.authorLo, Chi-Chunen_US
dc.date.accessioned2017-04-21T06:50:07Z-
dc.date.available2017-04-21T06:50:07Z-
dc.date.issued2013en_US
dc.identifier.isbn978-0-7695-5111-1en_US
dc.identifier.urihttp://dx.doi.org/10.1109/ICEBE.2013.52en_US
dc.identifier.urihttp://hdl.handle.net/11536/135399-
dc.description.abstractMost existing Threat and Risk Assessment (TRA) schemes for cloud services use a converse thinking approach to develop theoretical solutions for minimizing the risk of security breeches at a minimal cost. However, to support rational management decisions, TRA schemes require a careful analysis of the trade-off between the residual risk and the Return on Investment (ROI) given prescribed budget and time constraints. Accordingly, the present study proposes an improved Attack-Defense Tree mechanism designated as iADTree, for solving the TRA problem in cloud computing environments. The proposed scheme enables defenders to identify appropriate countermeasures in accordance with three different defensive strategies associated with the organization\'s security policy. In implementing the proposed scheme, a sandbox technique is used to examine the attack profile and attack probability of various forms of cyber attacks. The cost and residual risk of various defensive strategies are then evaluated and presented to the defender as a set of recommendations. Defense evaluation metrics for each node for probabilistic analysis is used to simulate the attack results. The simulations focus specifically on the attack profile of botnet to the threat risk assessment. The validity of the proposed approach is demonstrated by simulating the TRA process for a Zeus botnet attack. Overall, the results show that iADTree provides an effective means of modeling the interaction process between the attacker and the defender, analyzing the risk at each node of the tree given various defensive strategies, and developing cost-effective countermeasures for mitigating the network threat.en_US
dc.language.isoen_USen_US
dc.subjectCloud servicesen_US
dc.subjectThreat and Risk Assessmenten_US
dc.subjectAttack profileen_US
dc.subjectAttack-Defense Treeen_US
dc.titleA Novel Threat and Risk Assessment Mechanism for Security Controls in Service Managementen_US
dc.typeProceedings Paperen_US
dc.identifier.doi10.1109/ICEBE.2013.52en_US
dc.identifier.journal2013 IEEE 10TH INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE)en_US
dc.citation.spage337en_US
dc.citation.epage344en_US
dc.contributor.department資訊管理與財務金融系 註:原資管所+財金所zh_TW
dc.contributor.departmentDepartment of Information Management and Financeen_US
dc.identifier.wosnumberWOS:000330341500052en_US
dc.citation.woscount1en_US
顯示於類別:會議論文