Visualizing cyber security risks with bow-tie diagrams

14Citations
Citations of this article
33Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Safety and security risks are usually analyzed independently, by different people using different tools. Consequently, the system analyst may fail to realize cyber attacks as a contributing factor to safety impacts or, on the contrary, design overly secure systems that will compromise the performance of critical operations. This paper presents a methodology for visualizing and assessing security risks by means of bow-tie diagrams, which are commonly used within safety assessments. We outline how malicious activities, random failures, security countermeasures and safety barriers can be visualized using a common graphical notation and propose a method for quantifying risks based on threat likelihood and consequence severity. The methodology is demonstrated using a case study from maritime communication. Our main conclusion is that adding security concepts to the bow-ties is a promising approach, since this is a notation that high-risk industries are already familiar with. However, their advantage as easy-to-grasp visual models should be maintained, hence complexity needs to be kept low.

Cite

CITATION STYLE

APA

Bernsmed, K., Frøystad, C., Meland, P. H., Nesheim, D. A., & Rødseth, Ø. J. (2018). Visualizing cyber security risks with bow-tie diagrams. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 10744 LNCS, pp. 38–56). Springer Verlag. https://doi.org/10.1007/978-3-319-74860-3_3

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free