【24h】

Goal-Driven Deception Tactics Design

机译:目标驱动的欺骗战术设计

获取原文

摘要

Deception-based defense relies on intentional actions employed to induce erroneous inferences on attackers. Existing deception approaches are included in the software development process in an ad-hoc fashion, and are fundamentally realized as single tools or entire solutions repackaged as honeypot machines. We propose a systematic goal-driven approach to include deception tactics early in the software development process so that conflicts and risks can be found in the initial phases of the development, reducing costs of ill-planed decisions. The process integrates three phases: system modeling (producing a goal model of the application domain), security modeling (producing a threat model specifying the typical security concerns from the attacker perspective), and deception modeling (producing a deception tactic model, a variability model, and deception story models). The feasibility of the proposed approach is shown via a case study where deception defense strategies are designed for a students' presence control system for our University.
机译:基于欺骗的防御依赖于用于诱导攻击者的错误推论的故意行动。现有的欺骗方法以临时方式纳入软件开发过程中,并从根本上实现为单一工具或整个解决方案作为蜜罐机重新包装。我们提出了一种系统的目标驱动方法,以便在软件开发过程中提前包括欺骗性策略,以便在开发的初始阶段中发现冲突和风险,降低了污染决策的成本。该过程集成了三个阶段:系统建模(制作应用程序域的目标模型),安全建模(产生从攻击者视角指定典型安全问题的威胁模型),以及欺骗建模(产生欺骗性策略模型,变异模型和欺骗性的故事模型)。通过案例研究表明了拟议方法的可行性,其中欺骗防御策略为学生为大学的呈现控制系统设计。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号