首页> 外文会议>International workshop on graphical models for security;IEEE computer security foundations symposium >Graphical Modeling of Security Arguments:Current State and Future Directions
【24h】

Graphical Modeling of Security Arguments:Current State and Future Directions

机译:安全参数的图形化建模:当前状态和未来方向

获取原文

摘要

Identifying threats and risks to complex systems often requires some form of brainstorming. In addition, eliciting security requirements involves making traceable decisions about which risks to mitigate and how. The complexity and dynamics of modern socio-technical systems mean that their security cannot be formally proven. Instead, some researchers have turned to modeling the claims underpinning a risk assessment and the arguments which support security decisions. As a result, several argumentation-based risk analysis and security requirements elicitation frameworks have been proposed. These draw upon existing research in decision making and requirements engineering. Some provide tools to graphically model the underlying argumentation structures, with varying degrees of granularity and formalism. In this paper, we compare these approaches, discuss their applicability and suggest avenues for future research. We find that the core of existing security argumentation frameworks are the links between threats, risks, mitigations and system components. Graphs - a natural representation for these links - are used by many graphical security argumentation tools. But, in order to be human-readable, the graphical models of these graphs need to be both scalable and easy to understand. Therefore, in order to facilitate adoption, both the creation and exploration of these graphs need to be streamlined.
机译:识别复杂系统的威胁和风险通常需要某种形式的头脑风暴。另外,引发安全性要求包括就可减轻哪些风险以及如何减轻风险做出可追溯的决策。现代社会技术系统的复杂性和动态性意味着其安全性无法得到正式证明。取而代之的是,一些研究人员转向对风险评估和支持安全决策的论据进行建模。结果,提出了几种基于论证的风险分析和安全需求启发框架。这些借鉴了决策和需求工程中的现有研究。一些工具提供了以不同程度的粒度和形式主义以图形方式对基础的论证结构进行建模的工具。在本文中,我们比较了这些方法,讨论了它们的适用性,并为以后的研究提供了建议。我们发现,现有安全论证框架的核心是威胁,风险,缓解措施和系统组件之间的链接。图形(这些链接的自然表示)被许多图形安全性论证工具使用。但是,为了便于人们阅读,这些图的图形模型需要既可扩展又易于理解。因此,为了便于采用,需要简化这些图的创建和探索。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号