Khamparia Aditya, Pandey Babita
Department of Computer Science and Engineering, Lovely Professional University, Phagwara, Punjab India.
Department of Computer Applications, Lovely Professional University, Phagwara, India.
Springerplus. 2016 Apr 14;5:446. doi: 10.1186/s40064-016-2101-0. eCollection 2016.
Vulnerabilities at various levels are main cause of security risks in e-learning system. This paper presents a modified threat driven modeling framework, to identify the threats after risk assessment which requires mitigation and how to mitigate those threats. To model those threat mitigations aspects oriented stochastic petri nets are used. This paper included security metrics based on vulnerabilities present in e-learning system. The Common Vulnerability Scoring System designed to provide a normalized method for rating vulnerabilities which will be used as basis in metric definitions and calculations. A case study has been also proposed which shows the need and feasibility of using aspect oriented stochastic petri net models for threat modeling which improves reliability, consistency and robustness of the e-learning system.
各个层面的漏洞是电子学习系统安全风险的主要原因。本文提出了一种改进的威胁驱动建模框架,用于在风险评估后识别需要缓解的威胁以及如何缓解这些威胁。为了对那些威胁缓解方面进行建模,使用了面向方面的随机Petri网。本文纳入了基于电子学习系统中存在的漏洞的安全指标。通用漏洞评分系统旨在提供一种对漏洞进行评级的标准化方法,该方法将用作指标定义和计算的基础。还提出了一个案例研究,该研究表明了使用面向方面的随机Petri网模型进行威胁建模的必要性和可行性,这提高了电子学习系统的可靠性、一致性和鲁棒性。