Home > Projecten > Universiteit Twente > Informatietechnologie (algemeen) >
Jaarcongres 2011
Nieuws
Agenda
Over STW
Folder STW
Kennisexploitatie
Praktijkvoorbeelden
Logos
Organisatie
Adres en routebeschrijving
Jaarverslagen
Utilisatierapporten
Address and route description
English brochure
STW publicaties
Infobalie
Algemeen
Aanvragers
Referenten en Juryleden
Projectleiders
Gebruikers
Projecten
Programma's
Vacatures
Links
English
Login
Contact

VRIEND: Value-based security risk mitigation in en terprise networks that are decentralized (TIT.7635)

Project nummer: tit7635

Omschrijving van het onderzoek

In industrial practice, security engineering is risk management: how to mitigate security risk given a finite budget? Today the IT of a business is connected to that of others in a value web of business partners, suppliers and customers, each of whom has its own confidentiality, integrity and availability requirements. This creates new security challenges, because there is no central decision-making authority in these networks. The question to be investigated in VRIEND is how to extend current risk management practices with methods and techniques in decentralized networks.

We will investigate this, firstly, by developing methods and techniques to build up a security baseline for a value web, which is a set of security patterns agreed upon by members of a value web, of which the risk-mitigating properties have been quantitavely specified, and which are related to business goals and external legislation that therse patterns help to achieve. Secondly, we will develop quantitative techniques for security architecture design in decentralized networks, by means of which in a business project can compose the security mechanisms in the baseline into a security architecture of the business project result.

In a value web where each business has its own commercial interests, architecture design must use cost/benefit techniques to lead to agreement among different business partners. We will develop dynamic quantitative techniques, that allow businesses to incorporate the appearance of new security mechanisms, the occurrence of new threats or incidents, and of changes in security goals over time. changes in security goals over time.

Gebruikers

Five companies are involved in this project.

Projectleider

Prof.dr. R.J. Wieringa Universiteit Twente
Elektrotechniek Wiskunde en Informatica
security
Postbus 217
7500 AE Enschede

Status van het project

Gestart : dit project is nog niet gestart
Einddatum : 20-10-2010

Trefwoorden

Economics of security, Security (computer, software or network), Security incident management, Security patterns.

  Print | Over deze site |  Sitemap | Voorbehoud | Gewijzigd 9-2-2007
Nieuws uitgelicht
Nieuwsbrief Technologiestichting STW, januari 2012
31 januari 2012
Elke maand stuurt Technologiestichting STW haar relaties een link naar de web-based nieuwsbrief. Hierin staat een maandelijks overzicht van het jongste nieuws van de bestuurstafel, onderzoeksnieuws, o... [meer]