Quality of Protection Security Measurements and Metrics /

Information security in the business setting has matured in the last few decades. Standards, such as IS017799, the Common Criteria’s, and a number of industry and academic certifications and risk analysis methodologies, have raised the bar on what is considered good security solution, from a busines...

Πλήρης περιγραφή

Λεπτομέρειες βιβλιογραφικής εγγραφής
Συγγραφή απο Οργανισμό/Αρχή: SpringerLink (Online service)
Άλλοι συγγραφείς: Gollmann, Dieter (Επιμελητής έκδοσης), Massacci, Fabio (Επιμελητής έκδοσης), Yautsiukhin, Artsiom (Επιμελητής έκδοσης)
Μορφή: Ηλεκτρονική πηγή Ηλ. βιβλίο
Γλώσσα:English
Έκδοση: Boston, MA : Springer US, 2006.
Σειρά:Advances in Information Security, 23
Θέματα:
Διαθέσιμο Online:Full Text via HEAL-Link
LEADER 04461nam a22005775i 4500
001 978-0-387-36584-8
003 DE-He213
005 20151204154956.0
007 cr nn 008mamaa
008 100301s2006 xxu| s |||| 0|eng d
020 |a 9780387365848  |9 978-0-387-36584-8 
024 7 |a 10.1007/978-0-387-36584-8  |2 doi 
040 |d GrThAP 
050 4 |a QA76.9.A25 
072 7 |a URY  |2 bicssc 
072 7 |a COM053000  |2 bisacsh 
082 0 4 |a 005.82  |2 23 
245 1 0 |a Quality of Protection  |h [electronic resource] :  |b Security Measurements and Metrics /  |c edited by Dieter Gollmann, Fabio Massacci, Artsiom Yautsiukhin. 
264 1 |a Boston, MA :  |b Springer US,  |c 2006. 
300 |a XII, 198 p. 20 illus.  |b online resource. 
336 |a text  |b txt  |2 rdacontent 
337 |a computer  |b c  |2 rdamedia 
338 |a online resource  |b cr  |2 rdacarrier 
347 |a text file  |b PDF  |2 rda 
490 1 |a Advances in Information Security,  |x 1568-2633 ;  |v 23 
505 0 |a Motivations -- Why to adopt a security metric? A brief survey -- Service-oriented Assurance — Comprehensive Security by Explicit Assurances -- Measurements: Reliability vs Security -- Software Security Growth Modeling: Examining Vulnerabilities with Reliability Growth Models -- A Discrete Lognormal Model for Software Defects Affecting Quality of Protection -- Time-to-Compromise Model for Cyber Risk Reduction Estimation -- Assessing the risk of using vulnerable components -- Collection and analysis of attack data based on honeypots deployed on the Internet -- Quantitative Security Models -- Multilevel Security and Quality of Protection -- A Conceptual Model for Service Availability -- A SLA evaluation methodology in Service Oriented Architectures -- Towards a Notion of Quantitative Security Analysis -- Metrics for Anonymity and Confidentiality -- The Lower Bound of Attacks on Anonymity Systems — A Unicity Distance Approach -- Intersection Attacks on Web-Mixes: Bringing the Theory into Praxis -- Using Guesswork as a Measure for Confidentiality of Selectively Encrypted Messages -- Measuring Inference Exposure in Outsourced Encrypted Databases. 
520 |a Information security in the business setting has matured in the last few decades. Standards, such as IS017799, the Common Criteria’s, and a number of industry and academic certifications and risk analysis methodologies, have raised the bar on what is considered good security solution, from a business perspective. Yet, the evaluation of security solutions has largely a qualitative flavor. Notions such as Security Metrics, Quality of Protection (QoP) or Protection Level Agreement (PLA) have only surfaced in the literature. Quality of Protection: Security Measurements and Metrics is an edited volume based on the Quality of Protection Workshop at ESORICS 2005, the flagship European Symposium on Research in Computer Security. This book discusses how security research can progress towards a notion of quality of protection in security, comparable to the notion of quality of service in networking and software measurements and metrics, in empirical software engineering. Quality of Protection: Security Measurements and Metrics is designed for a professional audience, composed of researchers and practitioners in industry. This book is also suitable for graduate-level students in computer science and telecommunications. . 
650 0 |a Computer science. 
650 0 |a Microprocessors. 
650 0 |a Computer communication systems. 
650 0 |a Software engineering. 
650 0 |a Data structures (Computer science). 
650 0 |a Data encryption (Computer science). 
650 0 |a Database management. 
650 1 4 |a Computer Science. 
650 2 4 |a Data Encryption. 
650 2 4 |a Data Structures, Cryptology and Information Theory. 
650 2 4 |a Computer Communication Networks. 
650 2 4 |a Database Management. 
650 2 4 |a Software Engineering/Programming and Operating Systems. 
650 2 4 |a Processor Architectures. 
700 1 |a Gollmann, Dieter.  |e editor. 
700 1 |a Massacci, Fabio.  |e editor. 
700 1 |a Yautsiukhin, Artsiom.  |e editor. 
710 2 |a SpringerLink (Online service) 
773 0 |t Springer eBooks 
776 0 8 |i Printed edition:  |z 9780387290164 
830 0 |a Advances in Information Security,  |x 1568-2633 ;  |v 23 
856 4 0 |u http://dx.doi.org/10.1007/978-0-387-36584-8  |z Full Text via HEAL-Link 
912 |a ZDB-2-SCS 
950 |a Computer Science (Springer-11645)