2008•Unpublished venueRequires access

SecConfig: A Pre-Active Information Security Protection Technique

Ching-Jiang Chen, Ming-Hwa Li

Open publisher page 1 citations

Abstract

Recently, malicious programs and targeted attacks in social engineering have proved that lots of traditional outer protection schemes cannot prevent these threats. According to the principles of ISO27001 and BS7799 standards, an automatic information security protection system named "SecConfig" (Security Configuration) is proposed in this paper for the information security protection at the end host. There are totally 31 potential information security threats classified into three main categories: 1) the central control of the information security protection, 2) the fix of the information security at the operation system level and the application level, and 3) the asset management and information security live monitor platform. In this paper, there are 520 end hosts and 20 experimental rounds (one round per month) used to evaluate the proposed system. The results show that, excluding artificial and inartificial causes, more than 95% hosts can be protected safely and efficiently in the later rounds.

About this research paper

What this paper is about

Recently, malicious programs and targeted attacks in social engineering have proved that lots of traditional outer protection schemes cannot prevent these threats. According to the principles of ISO27001 and BS7799 standards, an automatic information security protection system named "SecConfig" (Security Configuration) is proposed in this paper for the information security protection at the end host. There are totally 31 potential information security threats classified into three main categories: 1) the central control of the information security protection, 2) the fix of the information security at the operation system level and the application level, and 3) the asset management and information security live monitor platform. In this paper, there are 520 end hosts and 20 experimental rounds (one round per month) used to evaluate the proposed system. The results show that, excluding artificial and inartificial causes, more than 95% hosts can be protected safely and efficiently in the later rounds.

Why it matters

OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Recently, malicious programs and targeted attacks in social engineering have proved that lots of traditional outer protection schemes cannot prevent these threats. According to the principles of ISO27001 and BS7799 standards, an automatic information security protection system named "SecConfig" (Security Configuration) is proposed in this paper for the information security protection at the end host. There are totally 31 potential information security threats classified into three main categories: 1) the central control of the information security protection, 2) the fix of the information security at the operation system level and the application level, and 3) the asset management and information security live monitor platform. In this paper, there are 520 end hosts and 20 experimental rounds (one round per month) used to evaluate the proposed system. The results show that, excluding artificial and inartificial causes, more than 95% hosts can be protected safely and efficiently in the later rounds.

Key concepts: Asset (computer security), Computer security, Information security, Computer science, Information security management, Security information and event management, Information protection policy, Security service

Related papers

Back to paper searchBrowse research topicsOriginal source
SecConfig: A Pre-Active Information Security Protection Technique — Research Paper | ScholarLens