首页> 外文期刊>International journal of computers, communications and control >Dynamic Expert System-Based Geographically Adapted Malware Risk Evaluation Method
【24h】

Dynamic Expert System-Based Geographically Adapted Malware Risk Evaluation Method

机译:基于动态专家系统的地理适应恶意软件风险评估方法

获取原文

摘要

Fast development of information systems and technologies while providing new opportunities for people and organizations also make them more vulnerable at the same time. Information security risk assessment helps to identify weak points and preparing mitigation actions. The analysis of expert systems has shown that rule-based expert systems are universal, and because of that can be considered as a proper solution for the task of risk assessment automation. But to assess information security risks quickly and accurately, it is necessary to process a large amount of data about newly discovered vulnerabilities or threats, to reflect regional and industry specific information, making the traditional approach of knowledge base formation for expert system problematic. This work presents a novel method for an automated expert systems knowledge base formation based on the integration of data on regional malware distribution from Cyberthreat real-time map providing current information on newly discovered threats. In our work we collect the necessary information from the web sites in an automated way, that can be later used in a relevant risk calculation. This paper presents method implementation, which includes not only knowledge base formation but also the development of the prototype of an expert system. It was created using the JESS expert system shell. Information security risk evaluation was performed according to OWASP risk assessment methodology, taking into account the location of the organization and prevalent malware in that area.
机译:信息系统和技术的快速发展,同时为人民和组织提供新的机会,也让他们同时更加脆弱。信息安全风险评估有助于识别弱点并准备缓解行动。专家系统的分析表明,基于规则的专家系统是普遍的,因为这可以被视为风险评估自动化任务的适当解决方案。但要快速准确地评估信息安全风险,有必要处理大量有关新发现的漏洞或威胁的数据,以反映区域和行业特定信息,使专家系统的知识库形成的传统方法。这项工作提出了一种基于从网络技术恶意软件分布的数据集成的自动专家系统知识库形成的新方法,从而提供了关于新发现威胁的当前信息。在我们的工作中,我们以自动化方式从网站收集必要的信息,以后可以在相关的风险计算中使用。本文提供了方法实现,不仅包括知识库形成,而且包括专家系统的原型的开发。它是使用Jess Expert System shell创建的。信息安全风险评估是根据OWASP风险评估方法进行的,考虑到该地区的组织和普遍存在的恶意软件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:[email protected]

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号

OSZAR »