首页 | 本学科首页   官方微博 | 高级检索  
     


A Formal Methodology for Detecting Managerial Vulnerabilities and Threats in an Enterprise Information System
Authors:Anirban Sengupta  Chandan Mazumdar  Aditya Bagchi
Affiliation:(1) Centre for Distributed Computing, Department of Computer Science and Engineering, Jadavpur University, Kolkata, West Bengal, 700032, India;(2) Indian Statistical Institute, 203 Barrackpore Trunk Road, Kolkata, West Bengal, 700108, India
Abstract:From information security point of view, an enterprise is considered as a collection of assets and their interrelationships. These interrelationships may be built into the enterprise information infrastructure, as in the case of connection of hardware elements in network architecture, or in the installation of software or in the information assets. As a result, access to one element may enable access to another if they are connected. An enterprise may specify conditions on the access of certain assets in certain mode (read, write etc.) as policies. The interconnection of assets, along with specified policies, may lead to managerial vulnerabilities in the enterprise information system. These vulnerabilities, if exploited by threats, may cause disruption to the normal functioning of information systems. This paper presents a formal methodology for detection of managerial vulnerabilities of, and threats to, enterprise information systems in linear time.
Keywords:
本文献已被 SpringerLink 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号