论文标题

多层模糊逻辑以量化物联网中的漏洞

multiple layers of fuzzy logic to quantify vulnerabilies in iot

论文作者

Shojaeshafiei, Mohammad, Etzkorn, Letha, Anderson, Michael

论文摘要

在网络安全和物联网领域,量化网络系统的漏洞一直是一个极大争议的问题。已经为此目的进行了许多研究;但是,这些具有许多歧义和不确定性。在本文中,我们调查了运输部(DOT)作为我们的概念证明的脆弱性量化。我们使用安全质量要求工程(Square)来启动安全要求的分析,以启发安全要求。然后,我们应用已发布的安全标准,例如NIST SP-800和ISO 27001来绘制我们的安全因素和子因素。最后,我们根据目标问题指标(GQM)提出了多层模糊逻辑(MFL)方法,以量化DOT中的网络安全性和IoT(移动设备)漏洞。

Quantifying vulnerabilities of network systems has been a highly controversial issue in the fields of network security and IoT. Much research has been conducted on this purpose; however, these have many ambiguities and uncertainties. In this paper, we investigate the quantification of vulnerability in the Department of Transportation (DOT) as our proof of concept. We initiate the analysis of security requirements, using Security Quality Requirements Engineering (SQUARE) for security requirements elicitation. Then we apply published security standards such as NIST SP-800 and ISO 27001 to map our security factors and sub-factors. Finally, we propose our Multi-layered Fuzzy Logic (MFL) approach based on Goal question Metrics (GQM) to quantify network security and IoT (Mobile Devices) vulnerability in DOT.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源