首页> 外文会议>IASTED international conference on software engineering and applications >REALIZING KNOCK-OUT EFFECT AND PARENT MITIGATION POWER FOR DETAILED ATTACK PATTERNS: A CASE STUDY
【24h】

REALIZING KNOCK-OUT EFFECT AND PARENT MITIGATION POWER FOR DETAILED ATTACK PATTERNS: A CASE STUDY

机译:实现淘汰效果和亲本缓解功率,以了解详细攻击模式:案例研究

获取原文
获取外文期刊封面目录资料

摘要

We propose the creation of two security metrics to measure NIST-based mitigation strategies when applied to the Common Attack Pattern Enumeration Classification (CAPEC) Release 1 Dictionary. Our approach refines and organizes CAPEC's vast repository of 101 attack patterns into usable hierarchies that are based on 11 Parent Threats and include the critical elements of each attack pattern. We also group the mitigation strategies of each attack pattern into Parent Mitigations by mapping the detailed necessary mitigation elements from CAPEC to the more generalized NIST mitigation families. Knock-out Effect (KOE) is a measure of how many Parent Mitigation strategies are needed to fully mitigate a detailed attack pattern. Each of the 101 attack patterns has a KOE calculated and stored as part of the detailed hierarchy. Parent Mitigation Power (PMP) is a measure of the total number of unique attack patterns that were partially mitigated by an individual Parent Mitigation strategy and the total number of Child Mitigation strategies that can be traced to the Parent Mitigation. A case study is used to illustrate our approach to leveraging these metrics by including 1 attack pattern from each of the 11 Parent Threats.
机译:我们建议在应用于共同攻击模式枚举分类(CAPEC)版本1字典时,建立两个安全度量来测量基于NIST的缓解策略。我们的方法会使Capec的巨大存储库中的101次攻击模式的巨大存储库中的可用层次结构基于11个父威胁,并包括每个攻击模式的关键元素。我们还通过将Capec的详细必要的缓解元素映射到更广泛的NIST缓解家庭来将每个攻击模式的缓解策略分组为家长缓解。敲除效果(KOE)是一种衡量需要多少家长缓解策略来完全减轻详细的攻击模式。 101攻击模式中的每一个都有一个KoE计算并作为详细层次结构的一部分存储。家长缓解权(PMP)是由个人父母缓解策略部分减轻的独特攻击模式的总数,以及可以追溯到父母缓解的儿童缓解策略的总数。案例研究用于说明我们通过11个父威胁中的每一个的1次攻击模式来利用这些指标的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号