首页> 外文会议>International Workshop on Security and Trust Management >Semi-automatically Augmenting Attack Trees Using an Annotated Attack Tree Library
【24h】

Semi-automatically Augmenting Attack Trees Using an Annotated Attack Tree Library

机译:使用带注释的攻击树库自动增强攻击树

获取原文
获取外文期刊封面目录资料

摘要

We present a method for assisting the semi-automatic creation of attack trees. Our method allows to explore a library of attack trees, select elements from this library that can be attached to an attack tree in construction, and determine how the attachment should be done. The process is supported by a predicate-based formal annotation of attack trees. To show the feasibility of our approach, we describe the process for automatically building a library of annotated attack trees from standard vulnerability descriptions in a publicly available online resource, using information extraction techniques. Then, we show how attack trees manually constructed from high level definitions of attack patterns can be augmented by attaching trees from this library.
机译:我们提出了一种帮助半自动创建攻击树的方法。我们的方法允许探索攻击树库,从该库中选择可以附加到施工的攻击树的元素,并确定应如何完成附件。该过程得到了攻击树的谓词形式注释的支持。为了展示我们方法的可行性,我们使用信息提取技术来描述从公共可用的在线资源中的标准漏洞描述中自动构建注释攻击树库的过程。然后,我们展示了如何通过从该库中附加树木来引用从高级定义手动构建的攻击树。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号