首页> 外文会议>IEEE International Requirements Engineering Conference >Holistic security requirements analysis: An attacker's perspective
【24h】

Holistic security requirements analysis: An attacker's perspective

机译:整体安全需求分析:攻击者的观点

获取原文

摘要

The ever-growing complexity of systems makes their protection more challenging, as a single vulnerability or exposure of any component of the system can lead to serious security breaches. This problem is exacerbated by the fact that the system development community has not kept up with advances in attack knowledge. In this demo paper, we propose a holistic attack analysis approach to identify and tackle both atomic and multistage attacks, taking into account not only software attacks but also attacks that are targeted at people and hardware. To bridge the knowledge gap between attackers and defenders, we systematically analyze and refine the malicious desires of attackers (i.e., anti-goals), and leverage a comprehensive attack pattern repository (CAPEC) to operationalize attacker goals into concrete attack actions. Based on the results of our attack analysis, appropriate security controls can be selected to effectively tackle potential attacks.
机译:系统的日益复杂性使它们的保护更具挑战性,因为单个漏洞或系统任何组件的暴露都可能导致严重的安全漏洞。系统开发社区未能跟上攻击知识的发展这一事实使这个问题更加严重。在本演示文件中,我们提出一种整体攻击分析方法,以识别和解决原子攻击和多阶段攻击,不仅要考虑软件攻击,还要考虑针对人员和硬件的攻击。为了弥合攻击者和防御者之间的知识鸿沟,我们系统地分析和完善了攻击者的恶意需求(即反目标),并利用全面的攻击模式存储库(CAPEC)将攻击者的目标具体化为具体的攻击行动。根据我们的攻击分析结果,可以选择适当的安全控制措施来有效地应对潜在的攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号