【24h】

A Template-Based Method for the Generation of Attack Trees

机译:基于模板的攻击树生成方法

获取原文

摘要

Attack trees are used in cybersecurity analysis to give an analyst a view of all the ways in which an attack can be carried out. Attack trees can become large, and developing them by hand can be tedious and error-prone. In this paper the automated generation of attack trees is considered. The method proposed is based on a library of attack templates - parameterisable patterns of attacks such as denial of service or eavesdropping - and that also uses an abstract model of the network architecture under attack. A pseudocode implementation of the method is also presented. The example application given is from the automotive domain and using an architecture consisting of linked CAN networks -a network configuration found in virtually every current vehicle.
机译:攻击树用于网络安全分析,以使分析人员可以了解攻击的所有执行方式。攻击树可能会很大,而手工开发它们可能会很乏味且容易出错。本文考虑了攻击树的自动生成。提出的方法基于攻击模板库-攻击的参数化模式(例如拒绝服务或窃听)-并且还使用了受攻击网络架构的抽象模型。还介绍了该方法的伪代码实现。给出的示例应用来自汽车领域,并使用了由链接的CAN网络组成的体系结构-实际上在当前每辆汽车中都存在一种网络配置。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号