Detection of Potential Threats to the Information System
DOI:
https://doi.org/10.37886/Keywords:
threat, information system, attacker, risk assessment, information securityAbstract
Research Question (RQ): Can the information system characteristics help us identify potential future threats?
Purpose: We want to examine the relationship of ordinary users and different groups of attackers to the properties of the information system. At the same time, we focus on measuring the importance of the information system properties for each population.
Method: We conducted a quantitative survey using a questionnaire. Descriptions of the information systems used in the questionnaire were defined on the basis of the available data on the web.
Results: We have confirmed the assumption that attackers mostly evaluate the same properties of the information system differently from the usual users. As a rule, attackers recognize in most properties more value than normal users, and in some cases these differences are obvious. Differences are also among the attackers. The results are a good basis for further research, namely checking which elements of the human threat are contributed by individual characteristics.
Organization: The properties of the observed information system where ordinary users and attackers experience obvious differences in valuation can be a good indicator of risk. By identifying such features, we can improve decision-making in risk assessment.
Society: The research aims to strengthen the belief that it is important to take into account the aspect of the attacker druring risk assessment, and to create a model of future human threats before they start designing the information system.
Originality: The survey confirms the idea that the aspect of the attacker should be taken into account in the risk assessment. The experiment showed that attackers give higher value to most of the information system properties than ordinary users.
Limitations/Future Research: We could include information security experts in the survey, rather than real attackers who are in fact a hidden population. In further research, we want to check how the characteristics of the information system contribute to individual elements of the human threat (motivation, recognition of opportunities, ability testing).
References
Alberts, C. J., & Dorofee, A. J. (2002). Managing Information Security Risks: The OCTAVE Approach. Addison-Wesley.
Alhazmi, O. H., Malaiya, Y. K., & Ray, I. (2007). Measuring, analyzing and predicting security vulnerabilities in software systems. Computers & Security, 26(3), 219–228. https://doi.org/10.1016/j.cose.2006.10.002
Anderson, R. J. (2010). Security Engineering: A Guide to Building Dependable Distributed Systems. Wiley.
Blyth, A., & Kovacich, G. L. (2006). Information Assurance: Security in the Information Environment. Springer.
Braber, F. Den, Hogganvik, I., & Lund, M. (2007). Model-based security analysis in seven steps—a guided tour to the CORAS method. BT Technology Journal, 25(1), 101–117.
Bruce, A. (2011). Risk Management and Methodologies. RiVidium Corporation.
BSI. (2008). BSI-Standard 100-3, Risk analysis based on IT-Grundschutz. Bundesamt fur Sicherheit in der Informationstechnik.
BSI. (2011). Supplement to BSI-Standard 100-3, Version 2.5, Application of the Elementary Threats from the IT-Grundschutz Catalogues for Performing Risk Analyses. Bundesamt fur Sicherheit in der Informationstechnik.
Buc, D., Corbier, J., & Deronzier Eric, Jouas Jean-Philippe, Molines Gerard, R. J.-L. (2009). RISK MANAGEMENT - Concepts and Methods. CLUSIF.
Casey, T. (2007). Threat Agent Library Helps Identify Information Security Risks. Intel White Paper. USA: Intel Corporation.
Casey, T., Koeberl, P., & Vishik, C. (2011). Defining Threat Agents: Towards a More Complete Threat Analysis. V ISSE 2010 Securing Electronic Business Processes (str. 214–225). Wiesbaden, Germany: Vieweg+Teubner. https://doi.org/10.1007/978-3-8348-9788-6_21
Dimensional Research. (2011). THE RISK OF SOCIAL ENGINEERING ON INFORMATION SECURITY : A SURVEY OF IT PROFESSIONALS. Dimensional Research.
Dubois, É., Heymans, P., Mayer, N., & Matulevičius, R. (2010). A Systematic Approach to Define the Domain of Information System Security Risk Management. V Intentional Perspectives on Information Systems Engineering (str. 289–306). Berlin, Heidelberg: Springer Berlin Heidelberg. https://doi.org/10.1007/978-3-642-12544-7_16
Ekelhart, A., Fenz, S., & Neubauer, T. (2009). AURUM: A framework for information security risk management. V System Sciences, 2009. HICSS ’09. 42nd Hawaii International Conference on SystemSciences (str. 1–10).
Evans, S., & Heinbuch, D. (2004). Risk-based systems security engineering: Stopping attacks with intention. Security & Privacy, IEEE, 2(6), 59–62.
Fenz, S., Ekelhart, A., & Neubauer, T. (2011). Information Security Risk Management: In which security solutions is it worth investing? Communications of the Association for Information Systems, 28(1), 329–356.
Frei, S., Schatzmann, D., Plattner, B., & Trammell, B. (2010). Modelling the Security Ecosystem - The Dynamics of ( In ) Security. V Economics of Information Security and Privacy (str. 79–106). Springer US. https://doi.org/10.1007/978-1-4419-6967-5_6
Gerber, M., & von Solms, R. (2005). Management of risk in the information age. Computers & Security, 24(1), 16–30. https://doi.org/10.1016/j.cose.2004.11.002
Hall, J. H., Sarkani, S., & Mazzuchi, T. a. (2011). Impacts of organizational capabilities in information security. Information Management & Computer Security, 19(3), 155–176. https://doi.org/10.1108/09685221111153546
ISO. (2011). ISO 27005:2011 - Information Technology: Security Techniques - Information Security Risk Management. ISO/IEC/JTC 1/SC 27.
IST-049. (2008). Improving Common Security Risk Analysis (Let. 323). The Research and Technology Organisation (RTO) of NATO.
Mann, I. (2008). Hacking the Human: Social Engineering Techniques and Security Countermeasures. Gower.
Mauw, S., & Oostdijk, M. (2006). Foundations of Attack Trees. Information Security and Cryptology - ICISC 2005, 3935(C), 186–198.
Miller, C. (2007). The Legitimate Vulnerability Market Inside the Secretive World of 0-day Exploit Sales. V In Sixth Workshop on the Economics of Information Security (str. 1–10).
Peltier, T. R. (2010). Information Security Risk Analysis, Third Edition. Taylor & Francis.
Pfleeger, C. P., & Pfleeger, S. L. (2006). Security in Computing (4th Edition). Upper Saddle River, NJ, USA: Prentice Hall PTR.
Rees, J., & Allen, J. (2008). The State of Risk Assessment Practices in Information Security: An Exploratory Investigation. Journal of Organizational Computing and Electronic Commerce, 18(4), 255–277. https://doi.org/10.1080/10919390802421242
RIS. (2014). e-bančništvo. Pridobljeno 22. marec 2014., od http://www.ris.org/c/1357/ebancnistvo/?preid=0
Salganik, M., & Heckathorn, D. (2004). Sampling and estimation in hidden populations using respondent‐driven sampling. Sociological methodology, 34(2004), 193–239.
Schneier, B. (2012). The Vulnerabilities Market and the Future of Security. Forbes.
Smith, R. (2012). A Contemporary Look at Saltzer and Schroeder’s 1975 Design Principles. Security & Privacy, IEEE, (December).
Smith, S. W. (2003). Humans in the Loop. IEEE Security & Privacy, 1(3), 75–79.
Stair, R., & Reynolds, G. (2013). Principles of Information Systems. Cengage Learning.
Steven, J. (2010). Threat Modeling - Perhaps It’s Time. IEEE Security & Privacy, 8(3), 83–86. https://doi.org/10.1109/MSP.2010.110
Stoneburner, G., Goguen, A., & Feringa, A. (2002). Risk Management Guide for Information Technology Systems Recommendations of the National Institute of Standards and Technology. NIST …. NIST.
Syalim, A., Hori, Y., & Sakurai, K. (2009). Comparison of Risk Analysis Methods: Mehari, Magerit, NIST800-30 and Microsoft’s Security Management Guide. V 2009 International Conference on Availability, Reliability and Security (str. 726–731). Ieee. https://doi.org/10.1109/ARES.2009.75
Vidalis, S., & Jones, A. (2005). Analyzing Threat Agents & Their Attributes. V Proceedings of the 5th European Conference on Information warfare and Security (str. 1–15).
Whittaker, J. A., & Ford, R. (2006). How to think about security. Security & Privacy, IEEE, 4(2), 68–71.
Workman, M. (2008). A test of interventions for security threats from social engineering. Information Management & Computer Security, 16(5), 463–483. https://doi.org/10.1108/09685220810920549