Cyber-Security Incident Analysis by Causal Analysis using System Theory (CAST)
Cyber-Security Incident Analysis by Causal Analysis using System Theory (CAST)
复制标题
使用系统理论 (CAST) 进行因果分析的网络安全事件分析
DOI:
10.1109/qrs-c55045.2021.00123
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
Tomoko Kaneko,NobukazuYoshioka,Ryoichi Sasaki
中科院分区:
文献类型:
--
作者:
金子朋子;安部浩之;Tomoko Kaneko Yuji Takahashi Shinichi Yamaguchi Jyunji Hashimoto Nobukazu Yoshioka;金子朋子,髙橋雄志,山口晋一,橋本順之,吉岡信和;佐々木良一,金子朋子,髙橋雄志,福澤寧子;Tomoko Kaneko,NobukazuYoshioka,Ryoichi Sasaki
STAMP (System Theoretic Accident Model and Processes) is one of the theories that has been attracting attention as a new safety analysis method for complex systems. CAST (Causal Analysis using System Theory) is a causal analysis method based on STAMP theory. The authors investigated an information security incident case, “AIST (National Institute of Advanced Industrial Science and Technology) report on unauthorized access to information systems,” and attempted accident analysis using CAST. We investigated whether CAST could be applied to the cyber security analysis. Since CAST is a safety accident analysis technique, this study was the first to apply CAST to cyber security incidents. Its effectiveness was confirmed from the viewpoint of the following three research questions. Q1:Features of CAST as an accident analysis method Q2:Applicability and impact on security accident analysis Q3:Understanding cyber security incidents with a five-layer model.