首页> 外文会议>International Conference on Information Systems Security and Privacy >A Methodology of Security Pattern Classification and of Attack-Defense Tree Generation
【24h】

A Methodology of Security Pattern Classification and of Attack-Defense Tree Generation

机译:安全模式分类和攻击防御树生成方法

获取原文

摘要

Security at the design stage of the software life cycle can be performed by means of security patterns, which are viable and reusable solutions to regular security problems. Their generic nature and growing number make their choice difficult though, even for experts in system design. To guide them through the appropriate choice of patterns, we present a methodology of security pattern classification and the classification itself, which exposes relationships among attacks, weaknesses and security patterns. Given an attack of the CAPEC (Common Attack Patterns Enumeration and Classification) database, the classification expresses the security pattern combinations that overcome the attack. The methodology, which generates the classification is composed of five steps, which decompose patterns and attacks into sets of more precise sub-properties that are associated. These steps provide the justifications of the classification and can be followed again to upgrade it. From the classification, we also generate Attack-Defense Trees (ADTtrees), which depict an attack, its sub-attacks and the related defenses in the form of security pattern combinations. Without loss of generality, this classification has been established for Web applications and covers 215 attacks, 136 software weaknesses and 26 security patterns.
机译:软件生命周期的设计阶段的安全性可以通过安全模式执行,这是对常规安全问题的可行和可重复使用的解决方案。他们的通用性质和越来越多的数字使他们选择困难,即使是系统设计的专家。要通过适当的模式选择,我们介绍了安全模式分类和分类本身的方法,这暴露了攻击,弱点和安全模式之间的关系。鉴于CAPEC的攻击(常见的攻击模式枚举和分类)数据库,分类表达了克服攻击的安全模式组合。生成分类的方法由五个步骤组成,该步骤将模式和攻击分解为相关联的更精确的子属性集。这些步骤提供了分类的理由,可以再次升级它来升级它。从分类中,我们还生成攻击 - 防御树(ADTTREES),它以安全模式组合的形式描绘了攻击,其子攻击和相关的防御。没有普遍存存,已经为Web应用程序建立了这个分类,并涵盖了215次攻击,136个软件缺陷和26个安全模式。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号