【24h】

Security attack analysis using attack patterns

机译:使用攻击模式进行安全攻击分析

获取原文

摘要

Discovering potential attacks on a system is an essential step in engineering secure systems, as the identified attacks will determine essential security requirements. The prevalence of Socio-Technical Systems (STSs) makes attack analysis particularly challenging. These systems are composed of people and organizations, their software systems, as well as physical infrastructures. As such, a thorough attack analysis needs to consider strategic (social and organizational) aspects of the involved people and organizations, as well as technical aspects affecting software systems and the physical infrastructure, requiring a large amount of security knowledge which is difficult to acquire. In this paper, we propose a systematic approach to efficiently leverage a comprehensive attack knowledge repository (CAPEC) in order to identify realistic and detailed attack behaviors, avoiding severe repercussions of security breaches. In particular, we propose a systematic method to model CAPEC attack patterns, which has been applied to 102 patterns, in order to semi-automatically select and apply such patterns. Using the CAPEC patterns as part of a systematic and tool-supported process, we can efficiently operationalize attack strategies and identify realistic alternative attacks on an STS. We validate our proposal by performing a case study on a smart grid scenario.
机译:发现对系统的潜在攻击是工程安全系统的必不可少的步骤,因为识别出的攻击将确定基本的安全要求。社会技术系统(STS)的盛行使攻击分析特别具有挑战性。这些系统由人员和组织,其软件系统以及物理基础结构组成。因此,全面的攻击分析需要考虑相关人员和组织的战略(社会和组织)方面,以及影响软件系统和物理基础结构的技术方面,这需要大量难以掌握的安全知识。在本文中,我们提出了一种系统的方法来有效利用综合的攻击知识库(CAPEC),以便识别现实的和详细的攻击行为,从而避免对安全漏洞的严重影响。特别是,我们提出了一种对CAPEC攻击模式进行建模的系统方法,该方法已应用于102个模式,以便半自动选择和应用此类模式。使用CAPEC模式作为系统和工具支持的过程的一部分,我们可以有效地实施攻击策略,并确定对STS的实际替代攻击。我们通过对智能电网方案进行案例研究来验证我们的建议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号