首页> 外国专利> Value-Adaptive Security Threat Modeling and Vulnerability Ranking

Value-Adaptive Security Threat Modeling and Vulnerability Ranking

机译:价值自适应安全威胁建模和漏洞排名

摘要

Among others, techniques and systems are disclosed for analyzing security threats associated with software and computer vulnerabilities. Stakeholder values relevant for a software system are identified. The identified stakeholder values are quantified using a quantitative decision making approach to prioritize vulnerabilities of the software system. A structured attack graph is generated to include the quantified stakeholder values to define a scalable framework to evaluate attack scenarios. The structured attack graph includes two or more nodes. Based on the generated structured attack graph, structured attack paths are identified with each attack path representing each attack scenario.
机译:其中,公开了用于分析与软件和计算机漏洞相关联的安全威胁的技术和系统。确定与软件系统相关的利益相关者值。使用定量决策方法对确定的利益相关者值进行量化,以对软件系统的漏洞进行优先级排序。生成结构化的攻击图,其中包括量化的利益相关者值,以定义可扩展的框架来评估攻击方案。结构化攻击图包括两个或更多节点。基于生成的结构化攻击图,识别结构化攻击路径,其中每个攻击路径代表每种攻击场景。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号