Novel Attack Tree Analysis Scheme to Assess the Security Risks on the Cloud Platform
作者:Shin-Jer Yang and Ya-Hui Yeh
Journal of Internet Technology
卷:20 期:4 頁碼:1027-1036
出版日期:2019年7月 (SCI)
The security issues derived from cloud platforms are more serious, and this identifiable vulnerability risk classifies the threat paths and identifies and assesses the possible attack paths. Therefore, we employ the basis of Extended Attack Tree (EAT) Analysis and further propose the Novel Attack Tree (NAT) Analysis scheme to calculate the threat and vulnerability events that affect the Cloud Platform Service Security incidents through the characteristics of the NAT Analysis to defend and detect these security events.
This paper utilizes the NAT Analysis proves that it can effectively assess the risk value on the cloud platform. According to threat report of the Cloud Security Alliance (CSA), after it simulates the risk factors of the cloud platform to obtain the threat path, then performs quantitative analysis on the impact of assets with the NAT Analysis. Finally, it obtains the weight of the risk value and sorts the level according to the value and further illustrate the comparison with the EAT Analysis. The proposed NAT Analysis can improve an information security risk analysis that the EAT Analysis cannot fulfill, and it can also increase the availability of risk assessments and is expected to bring more secure cloud services to the Cloud platform.
Keywords - Novel Attack Tree Analysis; Cloud Security Risk Analysis; Information Security; Cloud Platform
類別 | 標題 | 登刊日期 |
校園頭條 | 賀!商學院育成中心彭仁鴻執行長 獲管理界最高榮譽「呂鳳章先生紀念獎章」 | 10/28/2024 |
校園頭條 | 恭賀李韋宏學長 榮獲第十二屆傑出大陸台商創新經營獎 | 11/22/2024 |
校園頭條 | 全國資訊創新競賽 東吳資管系再創佳績 | 11/21/2024 |
校園頭條 | 校級赴外交換研修說明暨分享會 鼓勵同學赴海外研修 | 11/21/2024 |
校園頭條 | 韌性校園 永續大學成果展暨AI黑客松競賽 展現高教深耕計畫豐碩成果 | 11/21/2024 |