Security based survivability risk analysis with extended HQPN

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

3 Scopus citations

Abstract

Analysis of software survivability in the early development phase is very important to validate and specify software architecture. Specifically, quantitative evaluation of survivability is very useful to determine the architecture and to estimate the risk. The risk factor can be quantified as a combination of the probability that a software system may be failed through security threat and the severity of the damages caused by the attack. In this paper, we devise a methodology for analysis of risk factor which originates from violations of security goal. We elaborate Extended Hierarchically combined Queueing Petri Nets (E-HQPN) to estimate the survival failure probability with regard to attack and combines it with the severity of the failure consequence obtained using the Functional Failure Analysis. We apply the methodology on the development of an e-business application using step-bystep approach.

Original languageEnglish
Title of host publicationProceedings of the 5th International Conference on Ubiquitous Information Management and Communication, ICUIMC 2011
PublisherAssociation for Computing Machinery
ISBN (Electronic)9781450305716
DOIs
StatePublished - 21 Feb 2011
Externally publishedYes
Event5th International Conference on Ubiquitous Information Management and Communication, ICUIMC 2011 - Seoul, Korea, Republic of
Duration: 21 Feb 201123 Feb 2011

Publication series

NameACM International Conference Proceeding Series

Conference

Conference5th International Conference on Ubiquitous Information Management and Communication, ICUIMC 2011
Country/TerritoryKorea, Republic of
CitySeoul
Period21/02/1123/02/11

Keywords

  • E-HQPN
  • Security risk
  • Security threat
  • Survivability

Fingerprint

Dive into the research topics of 'Security based survivability risk analysis with extended HQPN'. Together they form a unique fingerprint.

Cite this