Title
Reducing the Incidence of Unintended, Human-Caused Information Flows in Enterprise Systems
Abstract
Research in enterprise system security has largely focused on the development of theoretical models capable of demonstrating mathematically that they possess desired security properties. However, recent results confirm that many of these models cannot be applied in practice because of the unpredictability of human participants' behavior in business processes. Moreover, while malicious attacks remain a significant problem, the majority of user-caused information leaks in Enterprise Systems are unintentional (or have many unintentional components) and could potentially be prohibited if explicitly recognized and appropriately modeled. In this paper we argue that approaches for achieving information flow security in enterprises need to combine process and policy understandability with usability of the enforcement mechanisms. We present a modeling approach that allows security policies to be formulated in such a way that (1) they are aligned to the business processes executed in an enterprise, (2) are understandable by all relevant stakeholders, and (3) can be semi-automatically transformed into run-time enforcement mechanisms.
Year
DOI
Venue
2012
10.1109/EDOCW.2012.12
EDOC Workshops
Keywords
Field
DocType
business process,unintentional component,enterprise system security,run-time enforcement mechanism,information flow security,security policy,security property,enforcement mechanism,user-caused information leak,enterprise systems,human-caused information flows
Data mining,Security convergence,Enterprise system,Information security standards,Computer science,Asset (computer security),Computer security,Information security management,Security information and event management,Human-computer interaction in information security,Enterprise information security architecture
Conference
ISSN
Citations 
PageRank 
2325-6583
0
0.34
References 
Authors
23
8
Name
Order
Citations
PageRank
Colin Atkinson11740147.08
Florian Barth200.34
Ralph Gerbig3383.88
Felix Freiling443735.37
Sebastian Schinzel510510.80
Frank Hadasch621.40
Alexander Maedche72371249.31
Benjamin Müller8131.34