Hide metadata

dc.date.accessioned2013-03-12T07:59:55Z
dc.date.available2013-03-12T07:59:55Z
dc.date.issued2007en_US
dc.date.submitted2007-12-04en_US
dc.identifier.citationHogganvik, Ida. A Graphical Approach toSecurity Risk Analysis. Doktoravhandling, University of Oslo, 2007en_US
dc.identifier.urihttp://hdl.handle.net/10852/9809
dc.description.abstract"The CORAS language is a graphical modeling language used to support the security analysis process with its customized diagrams. The language has been developed within the research project "SECURIS" (SINTEF ICT/University of Oslo), where it has been applied and evaluated in seven major industrial field trials. Experiences from the field trials show that the CORAS language has contributed to a more actively involvement of the participants, and it has eased the communication within the analysis group. The language has been found easy to understand and suitable for presentation purposes. With time we have become more and more dependent on various kinds of computerized systems. When the complexity of the systems increases, the number of security risks is likely to increase. Security analyses are often considered complicated and time consuming. A well developed security analysis method should support the analysis process by simplifying communication, interaction and understanding between the participants in the analysis. This thesis describes the development of the CORAS language that is particularly suited for security analyses where "structured brainstorming" is part of the process. Important design decisions are based on empirical investigations. The thesis has resulted in the following artifacts: - A modeling guideline that explains how to draw the different kind of diagrams for each step of the analysis. - Rules for translation which enables consistent translation from graphical diagrams to text. - Concept definitions that contributes to a consistent use of security analysis terms. - An evaluation framework to evaluate and compare the quality of security analysis modeling languages.”nor
dc.language.isoengen_US
dc.relation.haspartIda Hogganvik and Ketil Stølen On the Comprehension of Security Risk Scenarios. 13th International Workshop on Program Comprehension (IWPC’04). The paper is not available in DUO. http://dx.doi.org/10.1109/WPC.2005.27
dc.relation.haspartIda Hogganvik and Ketil Stølen Risk Analysis Terminology for IT-systems: Does it match intuition? 4th International Symposium on Empirical Software Engineering (ISESE’05). The paper is not available in DUO. http://dx.doi.org/10.1109/ISESE.2005.1541810
dc.relation.haspartIda Hogganvik and Ketil Stølen A Graphical Approach to Risk Identification, Motivated by Empirical Investigations 9th International Conference on Model Driven Engineering Languages and Systems (MoDELS’06). The paper is not available in DUO.
dc.relation.haspartHeidi E. I. Dahl, Ida Hogganvik and Ketil Stølen Structured Semantics for the CORAS Security Risk Modelling Language 2nd International Workshop on Interoperability Solutions on Trust, Security, Policies and QoS for Enhanced Systems (IS-TSPQ'07). The paper is not available in DUO.
dc.relation.haspartFolker den Braber,Ida Hogganvik, Mass Soldal Lund, Ketil Stølen and Fredrik Vraalsen Model-based security analysis in seven steps – a guided tour to the CORAS method Vol. 25 (1) of BT Technology Journal, 2007. The paper is not available in DUO.
dc.relation.haspartFredrik Vraalsen, Tobias Mahler,Mass Soldal Lund,Ida Hogganvik,Folker den Braber,Ketil Stølen Assessing Enterprise Risk Level: The CORAS Approach Advances in Enterprise Information Technology Security, Information Science Reference, 2007. The paper is not available in DUO.
dc.relation.haspartIda Hogganvik and Ketil Stølen Investigating preferences in graphical risk modeling Investigations Technical report, SINTEF A57, 2007. The paper is not available in DUO.
dc.relation.urihttp://dx.doi.org/10.1109/WPC.2005.27
dc.relation.urihttp://dx.doi.org/10.1109/ISESE.2005.1541810
dc.titleA Graphical Approach to Security Risk Analysisen_US
dc.typeDoctoral thesisen_US
dc.date.updated2012-09-17en_US
dc.creator.authorHogganvik, Idaen_US
dc.subject.nsiVDP::420en_US
cristin.unitcode150500en_US
cristin.unitnameInformatikken_US
dc.identifier.bibliographiccitationinfo:ofi/fmt:kev:mtx:ctx&ctx_ver=Z39.88-2004&rft_val_fmt=info:ofi/fmt:kev:mtx:dissertation&rft.au=Hogganvik, Ida&rft.title=A Graphical Approach toSecurity Risk Analysis&rft.inst=University of Oslo&rft.date=2007&rft.degree=Doktoravhandlingen_US
dc.identifier.urnURN:NBN:no-18378en_US
dc.type.documentDoktoravhandlingen_US
dc.identifier.duo68556en_US
dc.contributor.supervisorKetil Stølen and Jan Heimen_US
dc.identifier.bibsys080154220en_US
dc.identifier.fulltextFulltext https://www.duo.uio.no/bitstream/handle/10852/9809/1/DUO_662_Hogganvik_17x24.pdf


Files in this item

Appears in the following Collection

Hide metadata