首页> 外文会议>Euromicro International Conference on Parallel, Distributed, and Network-Based Processing >An Extension of Haruspex to Cover Vulnerabilities in Application Environments
【24h】

An Extension of Haruspex to Cover Vulnerabilities in Application Environments

机译:Haruspex的扩展以涵盖应用程序环境中的漏洞

获取原文

摘要

Haruspex is a suite of tools that assesses ICT risk through a scenario approach. Each scenario includes the target system and some threat agents that compose the attacks enabled by the system vulnerabilities to reach some predefined goals. The suite applies a Monte Carlo method with multiple simulations of the agent attacks against the target system. The simulation applies a formal model of the target system that describes the system nodes, the components with their vulnerabilities, and the logical topology. This paper proposes an extension to model in a more accurate way how the relations and the interactions among applications affect the agent attacks. After introducing this extension, we show how it supports the modeling of web applications. Then, we adopt the new model to assess a critical infrastructure that supervises and manages gas distribution.
机译:Haruspex是一套通过情景方法评估ICT风险的工具。每个方案都包括目标系统和一些威胁代理,这些威胁代理构成了由系统漏洞启用的攻击,可以达到某些预定义的目标。该套件将Monte Carlo方法与针对目标系统的代理攻击进行了多次仿真。该模拟应用了目标系统的正式模型,该模型描述了系统节点,具有其漏洞的组件以及逻辑拓扑。本文提出了一种扩展,以更准确的方式对应用程序之间的关系和交互如何影响代理攻击进行建模。引入此扩展之后,我们将展示它如何支持Web应用程序的建模。然后,我们采用新模型来评估监督和管理天然气分配的关键基础设施。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号