Information Security

Information security means the protection of information and information systems.

Security means that the properties confidentiality, integrity and availability (CIA) are fulfilled, considering the dependability and security taxonomy [ALRL2004].

These properties need to be defined with respect to a system, trust and adversary model, and specified in an explicit security goal.

Information can be at rest or in communication, which implies the security of systems as well as protocols and can include hardware security, as well.

Current Foci: Cloud and Cybercrime Security

  • Cloud Security Verification, which is information security for infrastructure cloud systems. It involves isolation analysis (confidentiality), topology configuration correctness (integrity/availability), and insider attacks (confidentiality, integrity and availability).

  • Cybercrime security (CCCS), which is security against crime committed by or through electronic means. Cybercrime inherently has a physical component as well as a human one.

[ALRL2004] A. Avizienis, J.-C. Laprie, B. Randell and C. Landwehr. Basic concepts and taxonomy of dependable and secure computing. IEEE Transactions on Dependable and Secure Computing. 1 (1), Jan. 2004, pp. 11-33.