首页> 外文会议>International symposiun on model-based safety and assessment >Automated Model-Based Attack Tree Analysis Using HiP-HOPS
【24h】

Automated Model-Based Attack Tree Analysis Using HiP-HOPS

机译:使用HiP-HOPS的基于模型的自动化攻击树分析

获取原文

摘要

As Cyber-Physical Systems (CPS) grow increasingly complex and interact with external CPS, system security remains a non-trivial challenge that continues to scale accordingly, with potentially devastating consequences if left unchecked. While there is a significant body of work on system security found in industry practice, manual diagnosis of security vulnerabilities is still widely applied. Such approaches are typically resource-intensive, scale poorly and introduce additional risk due to human error. In this paper, a model-based approach for Security Attack Tree (SAT) analysis using the HiP-HOPS dependability analysis tool is presented. The approach is demonstrated within the context of a simple web-based medical application to automatically generate attack trees, encapsulated as Digital Dependability Identities (DDIs), for offline security analysis. The paper goes on to present how the produced DDIs can be used to approach security maintenance, identifying security capabilities and controls to counter diagnosed vulnerabilities.
机译:随着网络物理系统(CPS)变得越来越复杂并与外部CPS进行交互,系统安全仍然是一项不容小challenge的挑战,并且会继续相应地扩展,如果任其发展,其后果可能是灾难性的。尽管在行业实践中发现了大量有关系统安全的工作,但是手动诊断安全漏洞仍然被广泛应用。这样的方法通常是资源密集的,扩展性差,并且由于人为错误而引入额外的风险。本文提出了一种基于模型的使用HiP-HOPS可靠性分析工具进行安全攻击树(SAT)分析的方法。在基于Web的简单医疗应用程序的上下文中演示了该方法,该应用程序可自动生成攻击树,封装为数字依赖身份(DDI),以进行脱机安全性分析。本文继续介绍如何将生成的DDI用来进行安全维护,识别安全功能和控制措施以解决已诊断的漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号