首页> 外文会议>International Workshop on Graphical Models for Security >Graphical Modeling of Security Arguments: Current State and Future Directions
【24h】

Graphical Modeling of Security Arguments: Current State and Future Directions

机译:安全论点的图形建模:当前状态和未来方向

获取原文
获取外文期刊封面目录资料

摘要

Identifying threats and risks to complex systems often requires some form of brainstorming. In addition, eliciting security requirements involves making traceable decisions about which risks to mitigate and how. The complexity and dynamics of modern socio-technical systems mean that their security cannot be formally proven. Instead, some researchers have turned to modeling the claims underpinning a risk assessment and the arguments which support security decisions. As a result, several argumentation-based risk analysis and security requirements elicitation frameworks have been proposed. These draw upon existing research in decision making and requirements engineering. Some provide tools to graphically model the underlying argumentation structures, with varying degrees of granularity and formalism. In this paper, we compare these approaches, discuss their applicability and suggest avenues for future research. We find that the core of existing security argumentation frameworks are the links between threats, risks, mitigations and system components. Graphs - a natural representation for these links - are used by many graphical security argumentation tools. But, in order to be human-readable, the graphical models of these graphs need to be both scalable and easy to understand. Therefore, in order to facilitate adoption, both the creation and exploration of these graphs need to be streamlined.
机译:识别复杂系统的威胁和风险通常需要某种形式的头脑风暴。此外,引出的安全要求涉及制定可追溯的决策,了解减轻和如何解决这些风险。现代社会技术系统的复杂性和动态意味着他们的安全性不能正式证明。相反,一些研究人员已经转向为支持风险评估的索赔和支持安全决策的论据建模。结果,已经提出了几种基于争论的风险分析和安全要求引发框架。这些借鉴了决策和要求工程的现有研究。有些提供工具来以图形方式模拟底层论证结构,具有不同程度的粒度和形式主义。在本文中,我们比较这些方法,讨论其适用性,并建议未来研究的途径。我们发现现有安全性论框架的核心是威胁,风险,缓解和系统组件之间的链接。图表 - 这些链接的自然表示 - 由许多图形安全性论工具使用。但是,为了成为人类可读的,这些图形的图形模型需要可扩展且易于理解。因此,为了促进采用,对这些图的创建和探索都需要精简。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号