Cargando…

A Quantitative Risk Assessment Model Involving Frequency and Threat Degree under Line-of-Business Services for Infrastructure of Emerging Sensor Networks

The prospect of Line-of-Business Services (LoBSs) for infrastructure of Emerging Sensor Networks (ESNs) is exciting. Access control remains a top challenge in this scenario as the service provider’s server contains a lot of valuable resources. LoBSs’ users are very diverse as they may come from a wi...

Descripción completa

Detalles Bibliográficos
Autores principales: Jing, Xu, Hu, Hanwen, Yang, Huijun, Au, Man Ho, Li, Shuqin, Xiong, Naixue, Imran, Muhammad, Vasilakos, Athanasios V.
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2017
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5375928/
https://www.ncbi.nlm.nih.gov/pubmed/28335569
http://dx.doi.org/10.3390/s17030642
_version_ 1782519087822274560
author Jing, Xu
Hu, Hanwen
Yang, Huijun
Au, Man Ho
Li, Shuqin
Xiong, Naixue
Imran, Muhammad
Vasilakos, Athanasios V.
author_facet Jing, Xu
Hu, Hanwen
Yang, Huijun
Au, Man Ho
Li, Shuqin
Xiong, Naixue
Imran, Muhammad
Vasilakos, Athanasios V.
author_sort Jing, Xu
collection PubMed
description The prospect of Line-of-Business Services (LoBSs) for infrastructure of Emerging Sensor Networks (ESNs) is exciting. Access control remains a top challenge in this scenario as the service provider’s server contains a lot of valuable resources. LoBSs’ users are very diverse as they may come from a wide range of locations with vastly different characteristics. Cost of joining could be low and in many cases, intruders are eligible users conducting malicious actions. As a result, user access should be adjusted dynamically. Assessing LoBSs’ risk dynamically based on both frequency and threat degree of malicious operations is therefore necessary. In this paper, we proposed a Quantitative Risk Assessment Model (QRAM) involving frequency and threat degree based on value at risk. To quantify the threat degree as an elementary intrusion effort, we amend the influence coefficient of risk indexes in the network security situation assessment model. To quantify threat frequency as intrusion trace effort, we make use of multiple behavior information fusion. Under the influence of intrusion trace, we adapt the historical simulation method of value at risk to dynamically access LoBSs’ risk. Simulation based on existing data is used to select appropriate parameters for QRAM. Our simulation results show that the duration influence on elementary intrusion effort is reasonable when the normalized parameter is 1000. Likewise, the time window of intrusion trace and the weight between objective risk and subjective risk can be set to 10 s and 0.5, respectively. While our focus is to develop QRAM for assessing the risk of LoBSs for infrastructure of ESNs dynamically involving frequency and threat degree, we believe it is also appropriate for other scenarios in cloud computing.
format Online
Article
Text
id pubmed-5375928
institution National Center for Biotechnology Information
language English
publishDate 2017
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-53759282017-04-10 A Quantitative Risk Assessment Model Involving Frequency and Threat Degree under Line-of-Business Services for Infrastructure of Emerging Sensor Networks Jing, Xu Hu, Hanwen Yang, Huijun Au, Man Ho Li, Shuqin Xiong, Naixue Imran, Muhammad Vasilakos, Athanasios V. Sensors (Basel) Article The prospect of Line-of-Business Services (LoBSs) for infrastructure of Emerging Sensor Networks (ESNs) is exciting. Access control remains a top challenge in this scenario as the service provider’s server contains a lot of valuable resources. LoBSs’ users are very diverse as they may come from a wide range of locations with vastly different characteristics. Cost of joining could be low and in many cases, intruders are eligible users conducting malicious actions. As a result, user access should be adjusted dynamically. Assessing LoBSs’ risk dynamically based on both frequency and threat degree of malicious operations is therefore necessary. In this paper, we proposed a Quantitative Risk Assessment Model (QRAM) involving frequency and threat degree based on value at risk. To quantify the threat degree as an elementary intrusion effort, we amend the influence coefficient of risk indexes in the network security situation assessment model. To quantify threat frequency as intrusion trace effort, we make use of multiple behavior information fusion. Under the influence of intrusion trace, we adapt the historical simulation method of value at risk to dynamically access LoBSs’ risk. Simulation based on existing data is used to select appropriate parameters for QRAM. Our simulation results show that the duration influence on elementary intrusion effort is reasonable when the normalized parameter is 1000. Likewise, the time window of intrusion trace and the weight between objective risk and subjective risk can be set to 10 s and 0.5, respectively. While our focus is to develop QRAM for assessing the risk of LoBSs for infrastructure of ESNs dynamically involving frequency and threat degree, we believe it is also appropriate for other scenarios in cloud computing. MDPI 2017-03-21 /pmc/articles/PMC5375928/ /pubmed/28335569 http://dx.doi.org/10.3390/s17030642 Text en © 2017 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Jing, Xu
Hu, Hanwen
Yang, Huijun
Au, Man Ho
Li, Shuqin
Xiong, Naixue
Imran, Muhammad
Vasilakos, Athanasios V.
A Quantitative Risk Assessment Model Involving Frequency and Threat Degree under Line-of-Business Services for Infrastructure of Emerging Sensor Networks
title A Quantitative Risk Assessment Model Involving Frequency and Threat Degree under Line-of-Business Services for Infrastructure of Emerging Sensor Networks
title_full A Quantitative Risk Assessment Model Involving Frequency and Threat Degree under Line-of-Business Services for Infrastructure of Emerging Sensor Networks
title_fullStr A Quantitative Risk Assessment Model Involving Frequency and Threat Degree under Line-of-Business Services for Infrastructure of Emerging Sensor Networks
title_full_unstemmed A Quantitative Risk Assessment Model Involving Frequency and Threat Degree under Line-of-Business Services for Infrastructure of Emerging Sensor Networks
title_short A Quantitative Risk Assessment Model Involving Frequency and Threat Degree under Line-of-Business Services for Infrastructure of Emerging Sensor Networks
title_sort quantitative risk assessment model involving frequency and threat degree under line-of-business services for infrastructure of emerging sensor networks
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5375928/
https://www.ncbi.nlm.nih.gov/pubmed/28335569
http://dx.doi.org/10.3390/s17030642
work_keys_str_mv AT jingxu aquantitativeriskassessmentmodelinvolvingfrequencyandthreatdegreeunderlineofbusinessservicesforinfrastructureofemergingsensornetworks
AT huhanwen aquantitativeriskassessmentmodelinvolvingfrequencyandthreatdegreeunderlineofbusinessservicesforinfrastructureofemergingsensornetworks
AT yanghuijun aquantitativeriskassessmentmodelinvolvingfrequencyandthreatdegreeunderlineofbusinessservicesforinfrastructureofemergingsensornetworks
AT aumanho aquantitativeriskassessmentmodelinvolvingfrequencyandthreatdegreeunderlineofbusinessservicesforinfrastructureofemergingsensornetworks
AT lishuqin aquantitativeriskassessmentmodelinvolvingfrequencyandthreatdegreeunderlineofbusinessservicesforinfrastructureofemergingsensornetworks
AT xiongnaixue aquantitativeriskassessmentmodelinvolvingfrequencyandthreatdegreeunderlineofbusinessservicesforinfrastructureofemergingsensornetworks
AT imranmuhammad aquantitativeriskassessmentmodelinvolvingfrequencyandthreatdegreeunderlineofbusinessservicesforinfrastructureofemergingsensornetworks
AT vasilakosathanasiosv aquantitativeriskassessmentmodelinvolvingfrequencyandthreatdegreeunderlineofbusinessservicesforinfrastructureofemergingsensornetworks
AT jingxu quantitativeriskassessmentmodelinvolvingfrequencyandthreatdegreeunderlineofbusinessservicesforinfrastructureofemergingsensornetworks
AT huhanwen quantitativeriskassessmentmodelinvolvingfrequencyandthreatdegreeunderlineofbusinessservicesforinfrastructureofemergingsensornetworks
AT yanghuijun quantitativeriskassessmentmodelinvolvingfrequencyandthreatdegreeunderlineofbusinessservicesforinfrastructureofemergingsensornetworks
AT aumanho quantitativeriskassessmentmodelinvolvingfrequencyandthreatdegreeunderlineofbusinessservicesforinfrastructureofemergingsensornetworks
AT lishuqin quantitativeriskassessmentmodelinvolvingfrequencyandthreatdegreeunderlineofbusinessservicesforinfrastructureofemergingsensornetworks
AT xiongnaixue quantitativeriskassessmentmodelinvolvingfrequencyandthreatdegreeunderlineofbusinessservicesforinfrastructureofemergingsensornetworks
AT imranmuhammad quantitativeriskassessmentmodelinvolvingfrequencyandthreatdegreeunderlineofbusinessservicesforinfrastructureofemergingsensornetworks
AT vasilakosathanasiosv quantitativeriskassessmentmodelinvolvingfrequencyandthreatdegreeunderlineofbusinessservicesforinfrastructureofemergingsensornetworks