Publication | Closed Access
A formal methodology for detection of vulnerabilities in an enterprise information system
12
Citations
10
References
2009
Year
Unknown Venue
Software MaintenanceEngineeringInformation SecurityVerificationInformation AssetsSoftware EngineeringSecurity EvaluationSoftware AnalysisFormal VerificationHardware SecurityVulnerability Assessment (Computing)Systems EngineeringFormal MethodologyEnterprise Information SystemSecurity ManagementSecurity TestingComputer ScienceData SecurityInformation Security PointSecurity Testing MethodInformation Security ManagementProgram AnalysisSoftware TestingInformation AssuranceSecuritySecurity MeasurementComputer Security Model
From information security point of view, an enterprise is considered as a collection of assets and their interrelations. These interrelations may be built into the enterprise information infrastructure, as in the case of connection of hardware elements in network architecture, or installation of software or information assets in hardware. As a result, access to one element may enable access to another if they are connected. An enterprise may specify conditions on the access of certain assets in certain mode (read, write etc.) as policies. The interconnection of assets, along with specified policies, may lead to managerial vulnerabilities in the enterprise information system. These vulnerabilities, if exploited by threats, may cause disruption to the normal functioning of information systems. This paper presents a formal method for detection of managerial vulnerabilities of enterprise information systems in linear time.
| Year | Citations | |
|---|---|---|
Page 1
Page 1