Towards an Automated Business Process Model Risk Assessment: A Process Mining Approach

3Citations
Citations of this article
7Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Cybersecurity Risk Assessment reports (RAs) on an organization’s information systems are fundamental to supporting its entire information security management. Proper assessments do not restrict their analysis only to tangible assets of an information system (e.g., servers, personal computers, databases) but also delve into the company’s day-to-day business flows that utilize its information system. Business processes, whether internal (i.e., payments) or external (i.e., paid services to customers or products), must also be analyzed in terms of impact and threat exposure, an approach often coined “process-based risk assessment.” Most modern ISO27000 methods and relevant tools include business flow models in their analysis, either as assets or as processes themselves. Process mining defines methods and techniques able to construct graphs that demonstrate the various business flows that are taking place in an information system. However, while process mining methods are of significant interest in general risk analysis, supply chain, and business restructuring, they seem to be neglected in cybersecurity risk assessments. In this paper, we propose an automated method for leveraging process mining to conduct faster and more thorough cybersecurity risk assessments. Our enhanced process mining creates graphs that incorporate weights from typical risk assessment methodologies and provide helpful information on risk and potential attack vectors on business-driven events by correlating and analyzing the steps of the business processes depicted in the graph to the assets used to complete each step. We evaluate our approach and proof-of-concept tool by modeling a real-world company’s business flows and incorporating them into a risk assessment model to detect and analyze potential attack sources and their respective impact on everyday business work.

Cite

CITATION STYLE

APA

Dedousis, P., Raptaki, M., Stergiopoulos, G., & Gritzalis, D. (2022). Towards an Automated Business Process Model Risk Assessment: A Process Mining Approach. In Proceedings of the International Conference on Security and Cryptography (Vol. 1, pp. 35–46). Science and Technology Publications, Lda. https://doi.org/10.5220/0011135600003283

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free