Advanced search
Start date
Betweenand


On the use of metrics and quantification in information security

Full text
Author(s):
Rodrigo Sanches Miani
Total Authors: 1
Document type: Doctoral Thesis
Press: Campinas, SP.
Institution: Universidade Estadual de Campinas (UNICAMP). Faculdade de Engenharia Elétrica e de Computação
Defense date:
Examining board members:
Leonardo de Souza Mendes; Leonardo Barbosa e Oliveira; Ana Paula Resende Malheiro; Marco Aurelio Amaral Henriques; Paulo Cardieri
Advisor: Leonardo de Souza Mendes; Bruno Bogaz Zarpelão
Abstract

With the increase in the number and diversity of attacks, a critical concern for organizations is to keep their network secure. To understand the actions that lead to successful attacks and also how they can be mitigated, researchers should identify and measure the factors that influence both attackers and victims. Quantifying security is particularly important to construct relevant metrics that support the decisions that need to be made to protect systems and networks. In this work, we aimed at proposing solutions to support the development of security quantification models applied in real environments. Three different approaches were used to investigate the problem: identifying issues on existing methods, evaluating metrics using empirical analysis and conducting a survey to investigate metrics in practice. Studies were conducted using data provided by the University of Maryland and also by the Security Incident Response Team (CAIS) from the National Education and Research Network (RNP). Our results showed that organizations could better manage security by employing security metrics and also that future directions in this field are related to the development of studies on real systems (AU)

FAPESP's process: 09/02131-0 - Development of methodologies using metrics for the calculation and application of security indicators.
Grantee:Rodrigo Sanches Miani
Support Opportunities: Scholarships in Brazil - Doctorate