English
Related papers

Related papers: A Methodology to Support Automatic Cyber Risk Asse…

200 papers

The Internet of Things (IoT) triggers new types of cyber risks. Therefore, the integration of new IoT devices and services requires a self-assessment of IoT cyber security posture. By security posture this article refers to the…

Cybersecurity threat and risk analysis (RA) approaches are used to identify and mitigate security risks early-on in the software development life-cycle. Existing approaches automate only parts of the analysis procedure, leaving key…

Software Engineering · Computer Science 2022-08-04 Katja Tuma , Romy Van Der Lee

Risk assessment plays a crucial role in ensuring the security and resilience of modern computer systems. Existing methods for conducting risk assessments often suffer from tedious and time-consuming processes, making it challenging to…

Cryptography and Security · Computer Science 2023-07-27 Simon Unger , Ektor Arzoglou , Markus Heinrich , Dirk Scheuermann , Stefan Katzenbeisser

The lack of security in information systems has caused numerous financial and moral losses to several organizations. The organizations have a series of information security measures recommended by literature and international standards.…

Over the last years, the number of cyber-attacks on industrial control systems has been steadily increasing. Among several factors, proper software development plays a vital role in keeping these systems secure. To achieve secure software,…

Software Engineering · Computer Science 2021-02-23 Tiago Espinha Gasiba , Ulrike Lechner , Maria Pinto-Albuquerque , Anmoal Porwal

An approach to the development of security test procedures for information security controls is presented. The recommendations for optimizing the test procedure are obtained

Cryptography and Security · Computer Science 2013-06-11 Alexander Barabanov , Maxim Grishin , Alexey Markov

The introduction of the European Union Artificial Intelligence Act, the NIST Artificial Intelligence Risk Management Framework, and related norms demands a better understanding and implementation of novel risk analysis approaches to…

Artificial Intelligence · Computer Science 2024-01-04 Jose Manuel Camacho , Aitor Couce-Vieira , David Arroyo , David Rios Insua

As today's organizational computer networks are ever evolving and becoming more and more complex, finding potential vulnerabilities and conducting security audits has become a crucial element in securing these networks. The first step in…

Cryptography and Security · Computer Science 2017-10-04 Stefan Marksteiner , Harald Lernbeiß , Bernhard Jandl-Scherf

There continue to be numerous breaches publicised pertaining to cyber security despite security practices being applied within industry for many years. This article is intended to be the first in a number of articles as research into cyber…

Cryptography and Security · Computer Science 2016-01-18 Mark Evans , Leandros A. Maglaras , Ying He , Helge Janicke

Cybersecurity governance influences the quality of strategic decision-making to ensure cyber risks are managed effectively. Board of Directors are the decisions-makers held accountable for managing this risk; however, they lack adequate and…

Cryptography and Security · Computer Science 2023-11-30 Anita Modi , Ievgeniia Kuzminykh , Bogdan Ghita

System security assurance provides the confidence that security features, practices, procedures, and architecture of software systems mediate and enforce the security policy and are resilient against security failure and attacks. Alongside…

Cryptography and Security · Computer Science 2022-08-04 Ankur Shukla , Basel Katt , Livinus Obiora Nweke , Prosper Kandabongee Yeng , Goitom Kahsay Weldehawaryat

From denial-of-service attacks to spreading of ransomware or other malware across an organization's network, it is possible that manually operated defenses are not able to respond in real time at the scale required, and when a breach is…

Cryptography and Security · Computer Science 2022-01-28 Alexandre K. Ligo , Alexander Kott , Igor Linkov

In cybersecurity, vulnerability assessment has typically focused on identifying and measuring vulnerabilities within digital assets and technical infrastructures. However, there is growing recognition that this approach alone is inadequate…

In the dynamic realm of cybersecurity, awareness training is crucial for strengthening defenses against cyber threats. This survey examines a spectrum of cybersecurity awareness training methods, analyzing traditional, technology-based, and…

Cryptography and Security · Computer Science 2024-01-23 Saif Al-Dean Qawasmeh , Ali Abdullah S. AlQahtani , Muhammad Khurram Khan

Traditional techniques for Cyber-Physical Systems (CPS) security design either treat the cyber and physical systems independently, or do not address the specific vulnerabilities of real time embedded controllers and networks used to monitor…

Cryptography and Security · Computer Science 2020-05-29 Ashraf Tantawy , Abdelkarim Erradi , Sherif Abdelwahed , Khaled Shaban

Critical software systems face stringent requirements in safety, security, and reliability due to the circumstances surrounding their operation. Safety and security have progressively gained importance over the years due to the integration…

Software Engineering · Computer Science 2015-12-16 Julio Escribano-Barreno , Marisol García-Valls

We are not very good at measuring -- rigorously and quantitatively -- the cyber security of systems. Our ability to measure cyber resilience is even worse. And without measuring cyber resilience, we can neither improve it nor trust its…

Cryptography and Security · Computer Science 2021-02-19 Alexander Kott , Igor Linkov

Based on classical contagion models we introduce an artificial cyber lab: the digital twin of a complex cyber system in which possible cyber resilience measures may be implemented and tested. Using the lab, in numerical case studies, we…

Cryptography and Security · Computer Science 2023-09-08 Kerstin Awiszus , Yannick Bell , Jan Lüttringhaus , Gregor Svindland , Alexander Voß , Stefan Weber

Some recent incidents have shown that possibly the vulnerability of IT systems in railway automation has been underestimated. Fortunately, so far, almost only denial-of-service attacks were successful, but due to several trends, such as the…

Cryptography and Security · Computer Science 2017-04-06 Jens Braband

Cyber Essentials (CE) comprise a set of controls designed to protect organisations, irrespective of their size, against cyber attacks. The controls are firewalls, secure configuration, user access control, malware protection & security…

Cryptography and Security · Computer Science 2024-06-24 Priyanka Badva , Partha Das Chowdhury , Kopo M. Ramokapane , Barnaby Craggs , Awais Rashid