【24h】

Asset-Oriented Threat Modeling

机译:资产导向威胁建模

获取原文

摘要

Threat modeling is recognized as one of the most important activities in software security. It helps to address security issues in software development. Several threat modeling processes are widely used in the industry such as the one of Microsoft SDL. In threat modeling, it is essential to first identify assets before enumerating threats, in order to diagnose the threat targets and spot the protection mechanisms. Asset identification and threat enumeration are collaborative activities involving many actors such as security experts and software architects. These activities are traditionally carried out in brainstorming sessions. Due to the lack of guidance, the lack of a sufficiently formalized process, the high dependence on actors' knowledge, and the variety of actors' background, these actors often have difficulties collaborating with each other. Brainstorming sessions are thus often conducted sub-optimally and require significant effort. To address this problem, we aim at structuring the asset identification phase by proposing a systematic asset identification process, which is based on a reference model. This process structures and identifies relevant assets, facilitating the threat enumeration during brainstorming. We illustrate the proposed process with a case study and show the usefulness of our process in supporting threat enumeration and improving existing threat modeling processes such as the Microsoft SDL one.
机译:威胁建模被认为是软件安全中最重要的活动之一。它有助于解决软件开发中的安全问题。几种威胁建模过程广泛用于业界,例如Microsoft SDL之一。在威胁建模中,首先枚举威胁之前首先识别资产,以便诊断威胁目标并发现保护机制。资产识别和威胁枚举是涉及许多行为者等安全专家和软件架构师的协作活动。这些活动传统上在头脑风暴会议中进行。由于缺乏指导,缺乏足够正式的过程,对演员知识的高度依赖,以及演员的背景,这些演员往往难以互相合作。因此,头脑风暴会话通常经常进行次优先进行,需要大量努力。为了解决这个问题,我们的目标是通过提出基于参考模型的系统资产识别过程来构建资产识别阶段。该过程结构并确定相关资产,促进头脑风暴期间的威胁枚举。我们用案例研究说明了所提出的进程,并显示了我们支持威胁枚举和改进Microsoft SDL One等现有威胁建模过程的过程的有用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号