Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review

被引:15
作者
Cheimonidis, Pavlos [1 ]
Rantos, Konstantinos [1 ]
机构
[1] Int Hellen Univ, Dept Comp Sci, Kavala 65404, Greece
关键词
cybersecurity; dynamic risk assessment; machine-learning; quantitative risk assessment; THREAT INTELLIGENCE; ASSESSMENT MODEL; MANAGEMENT; VULNERABILITY; CYBERATTACKS;
D O I
10.3390/fi15100324
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Traditional information security risk assessment (RA) methodologies and standards, adopted by information security management systems and frameworks as a foundation stone towards robust environments, face many difficulties in modern environments where the threat landscape changes rapidly and new vulnerabilities are being discovered. In order to overcome this problem, dynamic risk assessment (DRA) models have been proposed to continuously and dynamically assess risks to organisational operations in (near) real time. The aim of this work is to analyse the current state of DRA models that have been proposed for cybersecurity, through a systematic literature review. The screening process led us to study 50 DRA models, categorised based on the respective primary analysis methods they used. The study provides insights into the key characteristics of these models, including the maturity level of the examined models, the domain or application area in which these models flourish, and the information they utilise in order to produce results. The aim of this work is to answer critical research questions regarding the development of dynamic risk assessment methodologies and provide insights on the already developed methods as well as future research directions.
引用
收藏
页数:25
相关论文
共 78 条
[1]   A Novel Architecture for Predictive CyberSecurity using non-homogenous Markov Models [J].
Abraham, Subil ;
Nair, Suku .
2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, :774-781
[2]   Italian National Framework for Cybersecurity and Data Protection [J].
Angelini, Marco ;
Ciccotelli, Claudio ;
Franchina, Luisa ;
Marchetti-Spaccamela, Alberto ;
Querzoni, Leonardo .
PRIVACY TECHNOLOGIES AND POLICY, APF 2020, 2020, 12121 :127-142
[3]  
[Anonymous], 2009, Guide ISO 73: 2009
[4]  
[Anonymous], 2018, Risk management-Guidelines
[5]   A dynamic simulation approach to support the evaluation of cyber risks and security investments in SMEs [J].
Armenia, Stefano ;
Angelini, Marco ;
Nonino, Fabio ;
Palombi, Giulia ;
Schlitzer, Mario Francesco .
DECISION SUPPORT SYSTEMS, 2021, 147
[6]   Agent Based Cybersecurity Model for Business Entity Risk Assessment [J].
Ashiku, Lirim ;
Dagli, Cihan .
2020 6TH IEEE INTERNATIONAL SYMPOSIUM ON SYSTEMS ENGINEERING (IEEE ISSE 2020), 2020,
[7]  
Awan Malik Shahzad Kaleem, 2015, 2015 IEEE International Conferences on Computer and Information Technology
[8]  
Ubiquitous Computing and Communications
[9]  
Dependable, Autonomic and Secure Computing
[10]   An Empirical Risk Management Framework for Monitoring Network Security [J].
Awan, Malik Shahzad Kaleem ;
Burnap, Pete ;
Rana, Omer .
CIT/IUCC/DASC/PICOM 2015 IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION TECHNOLOGY - UBIQUITOUS COMPUTING AND COMMUNICATIONS - DEPENDABLE, AUTONOMIC AND SECURE COMPUTING - PERVASIVE INTELLIGENCE AND COMPUTING, 2015, :1765-1772