A Methodology for Dynamic Security Risks Assessment in Interconnected IT Systems
Abstract
The network of any IT system is subject to continuous changes, such as the addition of new nodes, software installations, and the emergence of new vulnerabilities. On the other hand, the importance of nodes within the IT system’s network varies due to various factors, impacting the severity of potential node exploitation. Additionally, the interconnected nature of the nodes means that the security of each node is interdependent on the others nodes. In this context, effective risk assessment methodologies that consider the factors which impact the security of the system are crucial. This paper introduces an innovative methodology that takes into account the aforementioned factors. The proposed approach evaluates vulnerabilities, interconnections, and dynamic changes to deliver a comprehensive and up-to-date security risk assessment. By employing this methodology, administrators gain better control over system security with dynamic evaluations that support wellinformed decisions. Furthermore, the methodology facilitates risk assessment for specific nodes and enables the quantification of their security levels. Due to a thorough assessment, the proposed methodology empowers IT administrators to improve the overall security of the system.
Keywords
Risk assessment, Interconnections, Attack graph, IDS, node improtant degree, Security risks, Impact of changes, Quantifying security implications, Exploitability, Security controlThis work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
S. Fayyad, A. Alkhatib, F. Abdel-Fattah and H. Almimi, "A Methodology for Dynamic Security Risks Assessment in Interconnected IT Systems," in Journal of Communications Software and Systems, vol. 20, no. 1, pp. 13-22, January 2024, doi: https://doi.org/10.24138/jcomss-2023-0128
@article{fayyad2024methodologydynamic, author = {Seraj Fayyad and Ahmad Alkhatib and Farhan Abdel-Fattah and Hani Almimi}, title = {A Methodology for Dynamic Security Risks Assessment in Interconnected IT Systems}, journal = {Journal of Communications Software and Systems}, month = {1}, year = {2024}, volume = {20}, number = {1}, pages = {13--22}, doi = {https://doi.org/10.24138/jcomss-2023-0128}, url = {https://doi.org/https://doi.org/10.24138/jcomss-2023-0128} }