Armature for Critical Infrastructures

Critical infrastructures have elevated requirements on security and availability. However, where security and availability are issues, security assurance evaluation becomes crucial. Evaluating security assurance is a non-trivial problem. In this paper, we discuss several security assurance aspects and the role of modeling in this context. We then introduce a novel, non-intrusive approach to security assurance evaluation. This approach comprises a modeling technique for the targeted infrastructure, the additional, non-intrusive evaluation infrastructure, and the implied evaluation methodology. We discuss possible implementations in an existing network.

[1]  Rayford B. Vaughn,et al.  Information assurance measures and metrics - state of practice and proposed taxonomy , 2003, 36th Annual Hawaii International Conference on System Sciences, 2003. Proceedings of the.

[2]  Michel Riguidel,et al.  A GLOBAL FRAMEWORK TO ENHANCE CRITICAL INFRASTRUCTURE PROTECTION , 2004 .