【24h】

Modeling Misuse Patterns

机译:建模滥用模式

获取原文

摘要

Security patterns are now starting to be accepted by industry. Security patterns are useful to guide the security design of systems by providing generic solutions that can stop a variety of attacks but it is not clear to an inexperienced designer what pattern should be applied to stop a specific attack. They are not useful either for forensics because they do not emphasize the modus operandi of the attack. To complement security patterns, we have proposed a new type of pattern, the misuse pattern. This pattern describes, from the point of view of the attacker, how a type of attack is performed (what units it uses and how), defines precisely the context of the attack, analyzes the ways of stopping the attack by enumerating possible security patterns that can be applied for this purpose, and describes how to trace the attack once it has happened by appropriate collection and observation of forensics data. We present here a model that characterizes the precise structure of this type of pattern.
机译:安全模式现在也开始被行业所接受。安全模式是通过提供通用的解决方案,可以阻止各种攻击来指导系统的安全性设计有用的,但目前尚不清楚对一个没有经验的设计师什么模式应该适用于阻止特定的攻击。他们是没有用的无论是取证,因为他们不强调进攻的手法。为配合安全模式,我们已经提出了一种新类型的图案,误用模式。此模式描述,从攻击者的,如何进行攻击的一种类型(它使用什么单位以及如何)点,定义了攻击的精确的背景下,通过枚举可能的安全模式分析停止攻击的方式是可用于该目的,并介绍了如何跟踪攻击一旦通过适当的收集和取证数据的观察发生。我们在座的表征这种类型的模式的精确结构模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号