首页> 外文会议>ACM symposium on access control models and technologies >Automating Architectural Security Analysis
【24h】

Automating Architectural Security Analysis

机译:自动化架构安全分析

获取原文

摘要

In earlier work [ I ] we had looked at implementing the Microsoft STRIDE methodology in the context of evaluating security properties of FMC/TAM architectural diagrams. However, a major drawback of this approach is that it requires significant manual work to assess all reported potential threats, as well as identify concrete follow-ups. Equally, it is not possible to analyse an architecture from the perspective of the primary assets that require protection. This led us to two questions: a) whether using interaction information in architecture diagrams, supported by additional security semantics, can reduce the scope of analysis as well as partly automate it; b) whether using asset-centric and attacker-centric perspectives can complement the software-centric perspective of STRIDE and thus add value to the current threat model.
机译:在较早的工作中,我们曾在评估FMC / TAM体系结构图的安全性的背景下实现Microsoft STRIDE方法。但是,此方法的主要缺点是,它需要大量的人工工作才能评估所有报告的潜在威胁,并确定具体的后续措施。同样,不可能从需要保护的主要资产的角度分析体系结构。这导致我们提出两个问题:a)在体系结构图中使用交互信息,并通过附加的安全语义支持是否可以缩小分析范围并部分自动化它; b)使用以资产为中心和以攻击者为中心的观点是否可以补充STRIDE的以软件为中心的观点,从而为当前的威胁模型增加价值。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号