返回
Quantitative risk-based security prediction for component-based systems with explicitly modeled attack profiles
DOI:10.1016/j.jss.2007.11.716.png)
摘要
En 中文
Systems and software architects require quantitative dependability evaluations, which allow them to compare the effect of their design decisions oil dependability properties. For security, however, quantitative evaluations have proven difficult, especially for component-based systems. in this paper, we present a risk-based approach that creates modular attack trees for each component in the system. These modular attack trees are specified as parametric constraints, which allow quantifying the probability of security breaches that occur due to internal component vulnerabilities as well as vulnerabilities in the component's deployment environment. In the second case. attack probabilities are passed between system components as appropriate to model attacks that exploit vulnerabilities in multiple system components. The probability of a Successful attack is determined with respect to a set of attack profiles that are chosen to represent potential attackers and corresponding environmental conditions. Based on these attack probabilities and the Structure of the modular attack trees, risk measures call be estimated for the complete system and compared with the tolerable risk demanded by stakeholders. The practicability of this approach is demonstrated with ail example that evaluates the confidentiality of a distributed document management system. (C) 2007 Elsevier Inc. All rights reserved.
Keyword:
model-driven security evaluation
SysML
parametric constraints
risk
confidentiality
composability
secrecy
privacy
component-based systems engineering
quantitative evaluation
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
4.1
论文数:
5.5K
被引数:
8.4K
机构
引用论文
Randomized Phase II Trial of Nivolumab With Stereotactic Body Radiotherapy Versus Nivolumab Alone in Metastatic Head and Neck Squamous Cell CarcinomaNivolumab联合立体定向放疗与单独Nivolumab治疗转移性头颈部鳞状细胞癌的随机II期试验
Cross-contamination of lettuce with Campylobacter spp. via cooking salt during handling raw poultry
PLOS ONE
IF0

