【24h】

Modeling Attack-Defense Trees' Countermeasures Using Continuous Time Markov Chains

机译:使用连续时间Markov链进行建模攻击树木的对策

获取原文

摘要

ADTrees (Attack-Defense Trees) are graphical security modeling tools used to logically represent attack scenarios along with their corresponding countermeasures in a user-friendly way. Many researchers nowadays use ADTrees to represent attack scenarios and perform quantitative as well as qualitative security assessment. Among all different existing quantitative security assessment techniques, CTMCs (Continuous Time Markov Chains) have been attractively adopted for ADTrees. ADTrees are usually transformed into CTMCs, where traditional stochastic quantitative analysis approaches can be applied. For that end, the correct transformation of an ADTree to a CTMC requires that each individual element of an ADTree should have its correct and complete representation in the corresponding CTMC. In this paper, we mainly focus on modeling countermeasures in ADTrees using CTMCs. The existing CTMC-model does not provide a precise and complete modeling capability, in particular, when cascaded-countermeasures are used. Cascaded-countermeasures occur when an attacker and a defender in a given ADTree recursively counter each other more than one time in a given branch of the tree. We propose the notion of tokenized-CTMC to construct a new CTMC-model that can precisely model and represent countermeasures in ADTrees. This new CTMC-model allows to handle cascaded-countermeasure scenarios in a more comprehensive way.
机译:Adtrees(攻击树木)是用于逻辑上表示攻击情景的图形安全建模工具以及以用户友好的方式以及它们的相应对策。现在许多研究人员使用AdTreeS表示攻击情景并进行定量以及定性安全评估。在所有不同的现有定量安全性评估技术中,CTMC(连续时间马尔可夫链)被吸引到AdtreeS采用。 Adtrees通常转化为CTMC,其中可以应用传统的随机定量分析方法。为此,Adtree对CTMC的正确转换要求Adtree的每个单个元素应在相应的CTMC中具有正确和完整的表示。在本文中,我们主要关注使用CTMC的Adtrees中的对策。现有的CTMC-Model在使用级联对策时,特别是当使用级联反应时,不提供精确和完全的建模能力。当给定的Adtree中的攻击者和防守者在树的给定分支中递归地反击攻击者和一个后卫时,发生级联 - 对策。我们提出了令牌化-CTMC的概念来构建一个新的CTMC模型,可以精确地模拟和代表Adtree中的对策。这种新的CTMC模型允许以更全面的方式处理级联 - 对策方案。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号