中文
相关论文

相关论文: Security Assessment Rating Framework for Enterpris…

200 篇论文

Cloud computing has been adopted widely, providing on-demand computing resources to improve perfornance and reduce the operational costs. However, these new functionalities also bring new ways to exploit the cloud computing environment. To…

密码学与安全 · 计算机科学 2019-03-12 Seoungmo An , Taehoon Eom , Jong Sou Park , Jin B. Hong , Armstrong Nhlabatsi , Noora Fetais , Khaled M. Khan , Dong Seong Kim

Despite the growing use of world models as decision-making agents, their adversarial robustness remains underexplored due to the lack of dedicated automated evaluation methods. A key obstacle is that attack evaluation must be both accurate…

机器学习 · 计算机科学 2026-05-25 Zhixiang Guo , Siyuan Liang , Shi Fu , Cheng Guo , Andras Balogh , Mark Jelasity , Dacheng Tao

Industrial reports indicate that security incidents continue to inflict large financial losses on organizations. Researchers and industrial analysts contend that there are fundamental problems with existing security incident response…

密码学与安全 · 计算机科学 2015-08-12 George Grispos , William Bradley Glisson , Tim Storer

By exploiting the increasing surface attack of systems, cyber-attacks can cause catastrophic events, such as, remotely disable safety mechanisms. This means that in order to avoid hazards, safety and security need to be integrated,…

计算机科学中的逻辑 · 计算机科学 2019-01-03 Vivek Nigam , Alexander Pretschner , Harald Ruess

Graph-based assessment formalisms have proven to be useful in the safety, dependability, and security communities to help stakeholders manage risk and maintain appropriate documentation throughout the system lifecycle. In this paper, we…

Traditional threat modeling occurs during design, but cloud deployments introduce unanticipated threats, especially multi-stage attacks chaining vulnerabilities across trust boundaries. Existing security tools analyze components in…

密码学与安全 · 计算机科学 2026-03-25 Nicholas Pecka , Lotfi Ben Othmane , Bharat Bhargava , Renee Bryce

Industry standard frameworks are now widespread for labeling the high-level stages and granular actions of attacker and defender behavior in cyberspace. While these labels are used for atomic actions, and to some extent for sequences of…

密码学与安全 · 计算机科学 2023-07-21 Georgel Savin , Ammar Asseri , Josiah Dykstra , Jonathan Goohs , Anthony Melarano , William Casey

Nowadays small and medium-sized enterprises have become an essential part of the national economy. With the increasing number of such enterprises, how to evaluate their credit risk becomes a hot issue. Unlike big enterprises with massive…

风险管理 · 定量金融 2022-05-03 Marui Du , Yue Ma , Zuoquan Zhang

A major cyber security incident can represent a cyber crisis for an organisation, in particular because of the associated risk of substantial reputational damage. As the likelihood of falling victim to a cyberattack has increased over time,…

密码学与安全 · 计算机科学 2020-09-22 Richard Knight , Jason R. C. Nurse

We introduce a risk assessment framework for digital identification systems, as well as recommended best practices to enhance privacy, security, and other desirable properties in these systems. To generate these resources, we created a…

计算机与社会 · 计算机科学 2025-07-22 Allison Woodruff , Dirk Balfanz , Will Drewry , Mariana Raykova

Cybersecurity incident response teams mitigate the impact of adverse cyber-related events in organisations. Field studies of IR teams suggest that at present the process of IR is under-developed with a focus on the technological dimension…

密码学与安全 · 计算机科学 2021-08-12 Ashley O'Neill , Atif Ahmad , Sean Maynard

Understanding the attack patterns associated with a cyberattack is crucial for comprehending the attacker's behaviors and implementing the right mitigation measures. However, majority of the information regarding new attacks is typically…

机器学习 · 计算机科学 2024-12-02 Weiqiu You , Youngja Park

With frequently evolving Advanced Persistent Threats (APTs) in cyberspace, traditional security solutions approaches have become inadequate for threat hunting for organizations. Moreover, SOC (Security Operation Centers) analysts are often…

Organizations employ various adversary models in order to assess the risk and potential impact of attacks on their networks. Attack graphs represent vulnerabilities and actions an attacker can take to identify and compromise an…

密码学与安全 · 计算机科学 2022-08-12 David Tayouri , Nick Baum , Asaf Shabtai , Rami Puzis

Embedded Systems (ES) development has been historically focused on functionality rather than security, and today it still applies in many sectors and applications. However, there is an increasing number of security threats over ES, and a…

密码学与安全 · 计算机科学 2021-12-13 Ángel Longueira-Romero , Rosa Iglesias , David Gonzalez , Iñaki Garitano

Model-based evaluation in cybersecurity has a long history. Attack Graphs (AGs) and Attack Trees (ATs) were the earlier developed graphical security models for cybersecurity analysis. However, they have limitations (e.g., scalability…

密码学与安全 · 计算机科学 2022-01-05 Simon Yusuf Enoch , Mengmeng Ge , Jin B. Hong , Dong Seong Kim

Information security risk assessment methods have served us well over the past two decades. They have provided a tool for organizations and governments to use in protecting themselves against pertinent risks. As the complexity,…

密码学与安全 · 计算机科学 2018-11-09 Jason R. C. Nurse , Sadie Creese , David De Roure

According to the World Economic Forum, cyber attacks are considered as one of the most important sources of risk to companies and institutions worldwide. Attacks can target the network, software, and/or hardware. During the past years, much…

密码学与安全 · 计算机科学 2022-08-31 Tara Ghasempouri , Jaan Raik , Cezar Reinbrecht , Said Hamdioui , Mottaqiallah Taouil

Security attacks are hard to understand, often expressed with unfriendly and limited details, making it difficult for security experts and for security analysts to create intelligible security specifications. For instance, to explain Why…

密码学与安全 · 计算机科学 2014-10-17 Muhammad Sabir Idrees , Yves Roudier , Ludovic Apvrille

Some recent incidents have shown that possibly the vulnerability of IT systems in railway automation has been underestimated. Fortunately, so far, almost only denial-of-service attacks were successful, but due to several trends, such as the…

密码学与安全 · 计算机科学 2017-04-06 Jens Braband