Scientists have been long investigating procedures, models and tools for the risk analysis in several domains, from economics to computer networks. This paper presents a quantitative method and a tool for the security risk assessment and management specifically tailored to the context of railway transportation systems, which are exposed to threats ranging from vandalism to terrorism. The method is based on a reference mathematical model and it is supported by a specifically developed tool. The tool allows for the management of data, including attributes of attack scenarios and effectiveness of protection mechanisms, and the computation of results, including risk and cost/benefit indices. The main focus is on the design of physical protection systems, but the analysis can be extended to logical threats as well. The cost/benefit analysis allows for the evaluation of the return on investment, which is a nowadays important issue to be addressed by risk analysts.

Quantitative security risk assessment and management for railway transportation infrastructures / Flammini F; Gaglione A; Mazzocca N; Pragliola C. - STAMPA. - 5508:(2009), pp. 180-189. (Intervento presentato al convegno 3rd International Workshop on Critical Information Infrastructures Security, CRITIS’08 tenutosi a Frascati (Rome), Italy nel October 13-15, 2008) [10.1007/978-3-642-03552-4_16].

Quantitative security risk assessment and management for railway transportation infrastructures

Flammini F;
2009

Abstract

Scientists have been long investigating procedures, models and tools for the risk analysis in several domains, from economics to computer networks. This paper presents a quantitative method and a tool for the security risk assessment and management specifically tailored to the context of railway transportation systems, which are exposed to threats ranging from vandalism to terrorism. The method is based on a reference mathematical model and it is supported by a specifically developed tool. The tool allows for the management of data, including attributes of attack scenarios and effectiveness of protection mechanisms, and the computation of results, including risk and cost/benefit indices. The main focus is on the design of physical protection systems, but the analysis can be extended to logical threats as well. The cost/benefit analysis allows for the evaluation of the return on investment, which is a nowadays important issue to be addressed by risk analysts.
2009
Proc. 3rd International Workshop on Critical Information Infrastructures Security, CRITIS’08
3rd International Workshop on Critical Information Infrastructures Security, CRITIS’08
Frascati (Rome), Italy
October 13-15, 2008
Flammini F; Gaglione A; Mazzocca N; Pragliola C
File in questo prodotto:
File Dimensione Formato  
10.1007%2F978-3-642-03552-4_16.pdf

Accesso chiuso

Licenza: Tutti i diritti riservati
Dimensione 435.25 kB
Formato Adobe PDF
435.25 kB Adobe PDF   Richiedi una copia

I documenti in FLORE sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificatore per citare o creare un link a questa risorsa: https://hdl.handle.net/2158/1386636
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 28
  • ???jsp.display-item.citation.isi??? 11
social impact