发明名称 Information system service-level security risk analysis
摘要 Information system service-level security risk analysis systems, methods, and Graphical User Interfaces are disclosed. Assets of an information system that have relationships with a service provided by the information system are identified, and at least one security risk to the service is determined by analyzing security vulnerabilities associated with the identified assets. A consolidated representation of the service is provided, and includes an indication of the determined security risk(s) and an indication of a relationship between the service and at least one of the identified assets. The security risk indication may include indications of multiple security parameters. Security risks may be represented differently depending on whether they arise from a security vulnerability of an asset that has a relationship with the service or a security vulnerability of an asset that has a relationship with the service only through a relationship with an asset that has a relationship with the service.
申请公布号 US8438643(B2) 申请公布日期 2013.05.07
申请号 US20060366101 申请日期 2006.03.02
申请人 WIEMER DOUGLAS;GUSTAVE CHRISTOPHE;CHOW STANLEY TAIHAI;MCFARLANE BRADLEY KENNETH;ALCATEL LUCENT 发明人 WIEMER DOUGLAS;GUSTAVE CHRISTOPHE;CHOW STANLEY TAIHAI;MCFARLANE BRADLEY KENNETH
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址