Cristin-resultat-ID: 1452681
Sist endret: 21. februar 2017, 10:53
Resultat
Vitenskapelig Kapittel/Artikkel/Konferanseartikkel
2015

Assessing the Usefulness of Testing for Validating and Correcting Security Risk Models Based on Two Industrial Case Studies

Bidragsytere:
  • Gencer Erdogan
  • Fredrik Seehusen
  • Ketil Stølen
  • Jon Hofstad og
  • Jan Øyvind Aagedal

Bok

Om resultatet

Vitenskapelig Kapittel/Artikkel/Konferanseartikkel
Publiseringsår: 2015
ISBN:
  • 9781466695627

Beskrivelse Beskrivelse

Tittel

Assessing the Usefulness of Testing for Validating and Correcting Security Risk Models Based on Two Industrial Case Studies

Sammendrag

The authors present the results of an evaluation in which the objective was to assess how useful testing is for validating and correcting security risk models. The evaluation is based on two industrial case studies. In the first case study the authors analyzed a multilingual financial Web application, while in the second case study they analyzed a mobile financial application. In both case studies, the testing yielded new information which was not found in the risk assessment phase. In particular, in the first case study, new vulnerabilities were found which resulted in an update of the likelihood values of threat scenarios and risks in the risk model. New vulnerabilities were also identified and added to the risk model in the second case study. These updates led to more accurate risk models, which indicate that the testing was indeed useful for validating and correcting the risk models.

Bidragsytere

Gencer Erdogan

  • Tilknyttet:
    Forfatter
    ved Sustainable Communication Technologies ved SINTEF AS

Fredrik Seehusen

  • Tilknyttet:
    Forfatter
    ved Sustainable Communication Technologies ved SINTEF AS

Ketil Stølen

  • Tilknyttet:
    Forfatter
    ved Sustainable Communication Technologies ved SINTEF AS

Jon Hofstad

  • Tilknyttet:
    Forfatter
    ved Diverse norske bedrifter og organisasjoner

Jan Øyvind Aagedal

  • Tilknyttet:
    Forfatter
    ved Diverse norske bedrifter og organisasjoner
1 - 5 av 5

Resultatet er en del av Resultatet er en del av

Business Intelligence: Concepts, Methodologies, Tools, and Applications.

Khosrow-Pour, Mehdi. 2015, IGI Global. Vitenskapelig antologi/Konferanseserie
1 - 1 av 1