首页> 外文会议>International workshop on security and trust management;European symposium on research in computer seurity >Semi-automatically Augmenting Attack Trees Using an Annotated Attack Tree Library
【24h】

Semi-automatically Augmenting Attack Trees Using an Annotated Attack Tree Library

机译:使用带注释的攻击树库半自动增强攻击树

获取原文

摘要

We present a method for assisting the semi-automatic creation of attack trees. Our method allows to explore a library of attack trees, select elements from this library that can be attached to an attack tree in construction, and determine how the attachment should be done. The process is supported by a predicate-based formal annotation of attack trees. To show the feasibility of our approach, we describe the process for automatically building a library of annotated attack trees from standard vulnerability descriptions in a publicly available online resource, using information extraction techniques. Then, we show how attack trees manually constructed from high level definitions of attack patterns can be augmented by attaching trees from this library.
机译:我们提出了一种辅助半自动创建攻击树的方法。我们的方法允许探索攻击树的库,从该库中选择可以在构造中附加到攻击树的元素,并确定应如何进行附加。该过程由攻击树的基于谓词的形式化注释支持。为了展示我们方法的可行性,我们描述了使用信息提取技术根据公开的在线资源中的标准漏洞描述自动构建带注释的攻击树库的过程。然后,我们展示了如何通过从该库中附加树来增强根据攻击模式的高级定义手动构建的攻击树。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号