Please use this identifier to cite or link to this item:
https://hdl.handle.net/20.500.11851/1948
Full metadata record
DC Field | Value | Language |
---|---|---|
dc.contributor.author | Aksu, M. Uğur | - |
dc.contributor.author | Dilek, M. Hadi | - |
dc.contributor.author | Tatli, E. Islam | - |
dc.contributor.author | Bıçakcı, Kemal | - |
dc.contributor.author | Dirik, H. İbrahim | - |
dc.contributor.author | Demirezen, M. Umut | - |
dc.contributor.author | Aykir, Tayfun | - |
dc.date.accessioned | 2019-07-10T14:42:41Z | |
dc.date.available | 2019-07-10T14:42:41Z | |
dc.date.issued | 2017 | |
dc.identifier.citation | Aksu, M. U., Dilek, M. H., Tatlı, E. İ., Bicakci, K., Dirik, H. İ., Demirezen, M. U., & Aykır, T. (2017, October). A quantitative CVSS-based cyber security risk assessment methodology for IT systems. In 2017 International Carnahan Conference on Security Technology (ICCST) (pp. 1-8). IEEE. | en_US |
dc.identifier.isbn | 978-1-5386-1585-0 | |
dc.identifier.issn | 1071-6572 | |
dc.identifier.uri | https://ieeexplore.ieee.org/document/8167819 | - |
dc.identifier.uri | https://hdl.handle.net/20.500.11851/1948 | - |
dc.description | International Carnahan Conference on Security Technology(2017 : Madrid; Spain) | |
dc.description.abstract | IT system risk assessments are indispensable due to increasing cyber threats within our ever-growing IT systems. Moreover, laws and regulations urge organizations to conduct risk assessments regularly. Even though there exist several risk management frameworks and methodologies, they are in general high level, not defining the risk metrics, risk metrics values and the detailed risk assessment formulas for different risk views. To address this need, we define a novel risk assessment methodology specific to IT systems. Our model is quantitative, both asset and vulnerability centric and defines low and high level risk metrics. High level risk metrics are defined in two general categories; base and attack graph-based. In our paper, we provide a detailed explanation of formulations in each category and make our implemented software publicly available for those who are interested in applying the proposed methodology to their IT systems. | en_US |
dc.description.sponsorship | This work was supported by The Scientific and Technological Research Council of Turkey (TÜBİTAK), TEYDEB 1501, Grant No: 3160047. | |
dc.language.iso | en | en_US |
dc.publisher | IEEE | en_US |
dc.relation.ispartof | Proceedings - International Carnahan Conference on Security Technology | en_US |
dc.rights | info:eu-repo/semantics/closedAccess | en_US |
dc.subject | attack graphs | en_US |
dc.subject | cyber security risks | en_US |
dc.subject | risk assessment | en_US |
dc.subject | risk metrics | en_US |
dc.subject | vulnerability management | en_US |
dc.title | A Quantitative Cvss-Based Cyber Security Risk Assessment Methodology for It Systems | en_US |
dc.type | Conference Object | en_US |
dc.department | Faculties, Faculty of Engineering, Department of Computer Engineering | en_US |
dc.department | Fakülteler, Mühendislik Fakültesi, Bilgisayar Mühendisliği Bölümü | tr_TR |
dc.relation.tubitak | info:eu-repo/grantAgreement/TÜBİTAK/TEYDEB/3160047 | en_US |
dc.authorid | 0000-0002-9045-4238 | - |
dc.identifier.wos | WOS:000424779200030 | en_US |
dc.identifier.scopus | 2-s2.0-85042294127 | en_US |
dc.institutionauthor | Bıçakçı, Kemal | - |
dc.identifier.doi | 10.1109/CCST.2017.8167819 | - |
dc.authorscopusid | 6603355557 | - |
dc.relation.publicationcategory | Konferans Öğesi - Uluslararası - Kurum Öğretim Elemanı | en_US |
dc.identifier.scopusquality | - | - |
item.openairetype | Conference Object | - |
item.languageiso639-1 | en | - |
item.grantfulltext | none | - |
item.fulltext | No Fulltext | - |
item.openairecristype | http://purl.org/coar/resource_type/c_18cf | - |
item.cerifentitytype | Publications | - |
crisitem.author.dept | 02.3. Department of Computer Engineering | - |
Appears in Collections: | Bilgisayar Mühendisliği Bölümü / Department of Computer Engineering Scopus İndeksli Yayınlar Koleksiyonu / Scopus Indexed Publications Collection WoS İndeksli Yayınlar Koleksiyonu / WoS Indexed Publications Collection |
CORE Recommender
SCOPUSTM
Citations
22
checked on Dec 21, 2024
WEB OF SCIENCETM
Citations
36
checked on Nov 9, 2024
Page view(s)
78
checked on Dec 23, 2024
Google ScholarTM
Check
Altmetric
Items in GCRIS Repository are protected by copyright, with all rights reserved, unless otherwise indicated.