2021
DOI: 10.1007/s10207-021-00566-3
|View full text |Cite
|
Sign up to set email alerts
|

A risk-level assessment system based on the STRIDE/DREAD model for digital data marketplaces

Abstract: Security is a top concern in digital infrastructure and there is a basic need to assess the level of security ensured for any given application. To accommodate this requirement, we propose a new risk assessment system. Our system identifies threats of an application workflow, computes the severity weights with the modified Microsoft STRIDE/DREAD model and estimates the final risk exposure after applying security countermeasures in the available digital infrastructures. This allows potential customers to rank t… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
7
0
1

Year Published

2023
2023
2025
2025

Publication Types

Select...
9
1

Relationship

0
10

Authors

Journals

citations
Cited by 15 publications
(8 citation statements)
references
References 18 publications
0
7
0
1
Order By: Relevance
“…The discoverability indicates the probability that a vulnerability can be discovered; the higher it is, the faster it can be discovered. DREAD has been used to evaluate attacks in various threat modeling or risk assessment studies [24,25].…”
Section: Common Vulnerability Scoring Systemmentioning
confidence: 99%
“…The discoverability indicates the probability that a vulnerability can be discovered; the higher it is, the faster it can be discovered. DREAD has been used to evaluate attacks in various threat modeling or risk assessment studies [24,25].…”
Section: Common Vulnerability Scoring Systemmentioning
confidence: 99%
“…While Open Threat Taxonomy employs a four-level hierarchy: threat categories, threat subcategories, threat types, and threat variants, NIST employs a three-level hierarchy: threat sources, threat events, and threat actors [15]. NIST categories relevant to healthcare include natural, human, and environmental threats [16]. Open Threat Taxonomy also has some healthcare-related categories, such as physical, environmental, and human threats.…”
Section: Ottmentioning
confidence: 99%
“…The STRIDE threat model can be used to classify threats into six categories -Spoofing, tampering, repudiation, information disclosure, denial of service or elevation of privilege (Abomhara, Gerdes & Køien, 2015). The DREAD threat model assigns numerical scores to identified threats and then translates theses scores to a qualitative risk level (Zhang et al, 2021). DREAD is short for:…”
Section: Threat Modellingmentioning
confidence: 99%