Mean Failure Cost as a Measurable Value and Evidence of Cybersecurity: E-Learning Case Study

N. Rjaibi, Latifa Ben Arfa Rabai, Anis Ben Aissa, A. Mili
{"title":"Mean Failure Cost as a Measurable Value and Evidence of Cybersecurity: E-Learning Case Study","authors":"N. Rjaibi, Latifa Ben Arfa Rabai, Anis Ben Aissa, A. Mili","doi":"10.4018/jsse.2013070104","DOIUrl":null,"url":null,"abstract":"Addressing Cybersecurity within e-Learning systems becomes empowered to make online information more secure. Certain competences need to be identified as necessary skills to manage security online such the ability to assess sources and architectural components, understanding the privacy, confidentiality and user authentication. Security management approaches quantifying security threats in e-learning are common with other e-services. It is of our need to adopt a quantitative security risk management process in order to determine the worthiest attack and the ignored one, based on financial business risk measure which is the measure of the mean failure cost.This paper proposes a cyber security measure called the Mean Failure Cost MFC suitable for e-Learning systems. It is based on the identification of system's architecture, the well-defined classes of stakeholders, the list of possible threats and vulnerabilities and the specific security requirements related to e-Learning systems and applications. In the mean time, security requirements are considered as appropriate mechanisms for preventing, detecting and recovering security attacks, for this reason an extension of the MFC measure is presented in order to detect the most critical security requirements. Also this paper highlights the security measures and guidelines for controlling e-Learning security policies regarding the most critical security requirements.","PeriodicalId":89158,"journal":{"name":"International journal of secure software engineering","volume":"PP 1","pages":"64-81"},"PeriodicalIF":0.0000,"publicationDate":"2013-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International journal of secure software engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4018/jsse.2013070104","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9

Abstract

Addressing Cybersecurity within e-Learning systems becomes empowered to make online information more secure. Certain competences need to be identified as necessary skills to manage security online such the ability to assess sources and architectural components, understanding the privacy, confidentiality and user authentication. Security management approaches quantifying security threats in e-learning are common with other e-services. It is of our need to adopt a quantitative security risk management process in order to determine the worthiest attack and the ignored one, based on financial business risk measure which is the measure of the mean failure cost.This paper proposes a cyber security measure called the Mean Failure Cost MFC suitable for e-Learning systems. It is based on the identification of system's architecture, the well-defined classes of stakeholders, the list of possible threats and vulnerabilities and the specific security requirements related to e-Learning systems and applications. In the mean time, security requirements are considered as appropriate mechanisms for preventing, detecting and recovering security attacks, for this reason an extension of the MFC measure is presented in order to detect the most critical security requirements. Also this paper highlights the security measures and guidelines for controlling e-Learning security policies regarding the most critical security requirements.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
平均故障成本作为网络安全的可测量值与证据:电子学习案例研究
在电子学习系统中解决网络安全问题可以使在线信息更加安全。需要将某些能力确定为在线管理安全性的必要技能,例如评估源和体系结构组件的能力,理解隐私、机密性和用户身份验证的能力。量化电子学习中的安全威胁的安全管理方法在其他电子服务中很常见。为了确定最值得攻击和被忽视的攻击,我们需要采用一种量化的安全风险管理流程,以金融业务风险度量为基础,即平均失效成本度量。本文提出了一种适用于网络学习系统的网络安全措施——平均失效成本(MFC)。它基于系统体系结构的识别、利益相关者的定义良好的类别、可能的威胁和漏洞列表以及与电子学习系统和应用程序相关的特定安全需求。同时,安全需求被认为是预防、检测和恢复安全攻击的适当机制,为此,提出了MFC措施的扩展,以检测最关键的安全需求。此外,本文还重点介绍了针对最关键的安全需求控制电子学习安全策略的安全措施和指导方针。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Analysis of Existing Software Cognitive Complexity Measures Risk Centric Activities in Secure Software Development in Public Organisations LDAP Vulnerability Detection in Web Applications A Database of Existing Vulnerabilities to Enable Controlled Testing Studies Goal Modelling for Security Problem Matching and Pattern Enforcement
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1