首页> 外文会议>ACM symposium on access control models and technologies >Automating Architectural Security Analysis
【24h】

Automating Architectural Security Analysis

机译:自动化建筑安全分析

获取原文

摘要

In earlier work [ I ] we had looked at implementing the Microsoft STRIDE methodology in the context of evaluating security properties of FMC/TAM architectural diagrams. However, a major drawback of this approach is that it requires significant manual work to assess all reported potential threats, as well as identify concrete follow-ups. Equally, it is not possible to analyse an architecture from the perspective of the primary assets that require protection. This led us to two questions: a) whether using interaction information in architecture diagrams, supported by additional security semantics, can reduce the scope of analysis as well as partly automate it; b) whether using asset-centric and attacker-centric perspectives can complement the software-centric perspective of STRIDE and thus add value to the current threat model.
机译:在早期的工作[I]中,我们在评估FMC / TAM架构图的安全属性的上下文中,我们研究过Microsoft升级方法。然而,这种方法的主要缺点是它需要重大的手工工作来评估所有报告的潜在威胁,以及识别具体的后续行动。同样,不可能从需要保护的主要资产的角度分析架构。这导致了两个问题:a)是否在架构图中使用架构图中的交互信息,通过额外的安全语义支持,可以减少分析的范围以及部分自动化; b)是否使用资产为中心和以攻击者为中心的观点来补充所在的脚步的基本的视角,从而增加了当前威胁模型的价值。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号