Threat Modeling Data Analysis in Socio-technical Systems

12/29/2017
by   Tomasz Ostwald, et al.
0

Our decision-making processes are becoming more data driven, based on data from multiple sources, of different types, processed by a variety of technologies. As technology becomes more relevant for decision processes, the more likely they are to be subjects of attacks aimed at disrupting their execution or changing their outcome. With the increasing complexity and dependencies on technical components, such attempts grow more sophisticated and their impact will be more severe. This is especially important in scenarios with shared goals, which had to be previously agreed to, or decisions with broad social impact. We need to think about our decisions-making and underlying data analysis processes in a systemic way to correctly evaluate benefits and risks of specific solutions and to design them to be resistant to attacks. To reach these goals, we can apply experiences from threat modeling analysis used in software security. We will need to adapt these practices to new types of threats, protecting different assets and operating in socio-technical systems. With these changes, threat modeling can become a foundation for implementing detailed technical, organizational or legal mitigations and making our decisions more reliable and trustworthy.

READ FULL TEXT

page 1

page 2

page 3

research
02/25/2023

A Threat-Intelligence Driven Methodology to Incorporate Uncertainty in Cyber Risk Analysis and Enhance Decision Making

The predictability and understandability of the world around us is limit...
research
06/25/2021

SaSeVAL: A Safety/Security-Aware Approach for Validation of Safety-Critical Systems

Increasing communication and self-driving capabilities for road vehicles...
research
01/30/2023

Typing of data transfer processes in the information system within the framework of threat modeling

Work is aimed at automating the process of obtaining a list of security ...
research
11/21/2022

Data analysis and visualization techniques for project tracking: Experiences with the ITLingo-Cloud Platform

Considering the market's competitiveness and the complexity of organizat...
research
01/26/2021

Reviewable Automated Decision-Making: A Framework for Accountable Algorithmic Systems

This paper introduces reviewability as a framework for improving the acc...
research
08/03/2022

The Role of Diversity in Cybersecurity Risk Analysis: An Experimental Plan

Cybersecurity threat and risk analysis (RA) approaches are used to ident...
research
04/16/2018

Decision Provenance: Capturing data flow for accountable systems

Demand is growing for more accountability in the technological systems t...

Please sign up or login with your details

Forgot password? Click here to reset