• No results found

Security Analysis Part I: Basics

N/A
N/A
Protected

Academic year: 2021

Share "Security Analysis Part I: Basics"

Copied!
35
0
0

Loading.... (view fulltext now)

Full text

(1)

Security Analysis

Part I: Basics

Ketil Stølen, SINTEF & UiO

October 2, 2015

(2)

Objectives for Lectures on

Security Analysis

Classify security concepts

Introduce, motivate and explain a basic apparatus

for risk management in general and risk analysis

in particular

Relate risk management to system development

Describe the different processes that risk

management involve

Motivate and illustrate model-driven security risk

analysis (or security analysis, for short)

(3)

Overview of today

What is security?

What is risk?

What is risk management?

What is the relationship to cyber security?

(4)

What is Security Analysis?

Security analysis is a specialized form of

risk analysis focusing on security risks

(5)

What is Security?

security

integrity availability accountability confidentiality Only authorised actors have access to Only authorised actors can change, create or delete Authorised actors have access to information they need when

It is possible to audit the sequence of events in

(6)

Security is more than Technology

Security solutions are available – but what

good is security if no one can use the

systems?

Security requires more than technical

understanding

Incidents often of non-technical origin

Requires a uniform description of the system

as a whole

(7)

Security – Part of System Development

Security is traditionally added as an

“afterthought”

Solutions often reactive rather than proactive

Security issues often solved in isolation

Costly redesign

Security not completely integrated

Enforcing security only at the end of the development process “by preventing certain behaviors...may result in a so useless system that the complete development effort would be wasted” [Mantel'01].

“It would be desirable to consider security aspects already in the design phase, before a system is actually implemented, since removing security flaws in the design phase saves cost and time” [Jürjens'02].

(8)

Oversettelse av Terminologi

asset aktivum (noe med verdi)

threat trussel

unwanted incident uønsket hendelse

risk risiko vulnerability sårbarhet consequence konsekvens probability sannsynlighet frequency frekvens/hyppighet treatment behandling

(9)

What is Risk?

Many kinds of risk

Contractual risk

Economic risk

Operational risk

Environmental risk

Health risk

Political risk

Legal risk

Security risk

(10)

Definition of Risk from ISO 31000

Risk:

Effect of uncertainty on objectives

 NOTE 1 An effect is a deviation from the expected — positive and/or negative

 NOTE 2 Objectives can have different aspects (such as financial, health and safety, and environmental goals) and can apply at different levels (such as strategic, organization-wide, project, product and process)

 NOTE 3 Risk is often characterized by reference to potential events

and consequences, or a combination of these

 NOTE 4 Risk is often expressed in terms of a combination of the

consequences of an event (including changes in circumstances) and the associated likelihood of occurrence

 NOTE 5 Uncertainty is the state, even partial, of deficiency of

information related to, understanding or knowledge of an event, its consequence, or likelihood

(11)

What is Risk Management?

Risk management:

Coordinated activities

to direct and control

an organization with

regard to

risk

[ISO 31000:2009]

Communicate and con s ult

Establish the context

Identify risks

Estimate risks

Evaluate risks

Treat risks

Monitor and review

Ri

sk ass

e

(12)

Risk Analysis Involves

Determining what can

happen, why and how

Systematic use of

available information to

determine the level of risk

Prioritization by

comparing the level of

risk against

predetermined criteria

Selection and

implementation of

appropriate options for

dealing with risk

Commun

icate an

d co

nsu

lt

Establish the context

Identify risks

Estimate risks

Evaluate risks

Treat risks

Mon

itor and review

Ri sk as se ss ment

(13)

Terms

Asset

Vulnerability

Threat

Risk

(14)

Terms

Risk Threat Vulnerability Unwanted incident Worm

Computer running Outlook

Internet

- Infected twice per year - Infected mail send to all

contacts Infected PC

V

Install virus scanner

(15)

Definitions

Asset: Something to which a party assigns value and hence for which the party requires protection

Consequence: The impact of an unwanted incident on an asset in terms of harm or reduced asset value

Likelihood: The frequency or probability of something to occur

Party:An organization, company, person, group or other body on whose behalf a risk analysis is conducted

Risk: The likelihood of an unwanted incident and its consequence for a specific asset

Risk level: The level or value of a risk as derived from its likelihood and consequence

Threat:A potential cause of an unwanted incident

Treatment: An appropriate measure to reduce risk level

(16)

Cyberspace, Cybersecurity

and Cyber-risk

What is new and what are the real

challenges?

(17)

There are no established definitions of cyberspace or cybersecurity

Many authoritative organizations have their own definitions

• EU, ISO, IEC, ITU-T, NIST, CNSS, …

The various definitions typically reflect different purposes or interests

• Information security

• Critical infrastructure protection

• Privacy and data protection

• Societal security

• Combating of cyber-crime and terrorism

(18)

Cybersecurity is a hot topic and a frequently used buzzword

Stakeholders want to ensure cybersecurity and protection from

cyber-risk

At the same time there is lack of terminology consensus and method

support

Our aim: Define a terminology and identify challenges

Motivation and Goals

(19)

Cyberspace

The term cyberspace first appeared in science fiction (novel by William Gibson)

(20)
(21)
(22)
(23)
(24)

But cybersecurity is not simply the combination of the two

Information security is the protection of confidentiality, integrity and

availability of information

Infrastructure security and CIP is to prevent the disruption, disabling,

destruction or malicious control of critical infrastructures

Cybersecurity is related to information security and

infrastructure security

(25)
(26)
(27)
(28)
(29)
(30)
(31)

The Challenge of Black-swans

(Nassim N. Taleb)

(32)

Security Analysis Using

CORAS

(33)

Overview

What is CORAS?

Main concepts

Process of eight steps

Risk modeling

Semantics

Calculus

Tool support

(34)

What is CORAS?

CORAS consists of

Method for risk analysis

Language for risk modeling

Tool for editing diagrams

Stepwise, structured and systematic process

Directed by assets

Concrete tasks with practical guidelines

Model-driven

Models as basis for analysis

Models as documentation of results

(35)

Mandatory Reading

Mass Soldal Lund, Bjørnar Solhaug, Ketil Stølen:

Chapter 3

"A Guided Tour of the CORAS Method" in the book

"Model-Driven Risk Analysis: The CORAS Approach"

, 2011. Springer.

The chapter can be downloaded freely.

Mass Soldal Lund, Bjørnar Solhaug, Ketil Stølen:

Risk

Analysis of Changing and Evolving Systems Using CORAS

,

2011. LNCS 6858, Springer. Pages 231-274.

Le Minh Sang Tran, Bjørnar Solhaug, Ketil Stølen. An

approach to select cost-effective risk countermeasures

exemplified in CORAS. SINTEF A24343, SINTEF ICT, July

2013.

References

Related documents

Keywords: Multicultural Family; National Health Programs; Preventive Health Services; Patient Satisfaction; Concern.. 다문화가족의 건강검진에 대한 관심과 만족도에

The Council specifically asked BiH also to “ establish functioning institutions as provided for in the constitution; to formulate a foreign trade and customs policy for

●17311 Mohs micrographic technique, including removal of all gross tumor, surgical excision of tissue specimens, mapping, color coding of specimens,. microscopic examination

This study explores the relationships between and among lists of top performers - Boston College’s Corporate Social Responsibility Index, Fortune’s World's Most

We extend the theory of leakage in unconfined aquifers by (1) including water flow and storage in the unsaturated zone above the water table, and (2) allowing the finite-diameter

Type of governance innovation HIV/AIDS Ebola AMR General/Other Creation of new institutions and governance arrangements New institutions and partnerships : UNAIDS, GFATM, Unitaid PDPs

“Downward pressure on revenue is the overarching theme,” says Derek Ellington, senior vice president and regional healthcare treasury manager for Bank of America Merrill

What follows is the story of how Floridians have cel- ebrated our most important holiday in the last four hundred years and how countless residents and visitors from near and