首页> 外文期刊>Computer standards & interfaces >An extensible pattern-based library and taxonomy of security threats for distributed systems
【24h】

An extensible pattern-based library and taxonomy of security threats for distributed systems

机译:可扩展的基于模式的库和分布式系统安全威胁的分类法

获取原文
获取原文并翻译 | 示例
           

摘要

Security is one of the most essential quality attributes of distributed systems, which often operate over untrusted networks such as the Internet To incorporate security features during the development of a distributed system requires a sound analysis of potential attacks or threats in various contexts, a process that is often termed "threat modeling". To reduce the level of security expertise required, threat modeling can be supported by threat libraries (structured or unstructured lists of threats), which have been found particularly effective in industry scenarios; or attack taxonomies, which offer a classification scheme to help developers find relevant attacks more easily. In this paper we combine the values of threat libraries and taxonomies, and propose an extensible, two-level "pattern-based taxonomy" for (general) distributed systems. The taxonomy is based on the novel concept of a threat pattern, which can be customized and instantiated in different architectural contexts to define specific threats to a system. This allows developers to quickly consider a range of relevant threats in various architectural contexts as befits a threat library, increasing the efficacy of, and reducing the expertise required for, threat modeling. The taxonomy aims to classify a wide variety of more abstract, system- and technology-independent threats, which keeps the number of threats requiring consideration manageable, increases the taxonomy's applicability, and makes it both more practical and more useful for security novices and experts alike. After describing the taxonomy which applies to distributed systems generally, we propose a simple and effective method to construct pattern-based threat taxonomies for more specific system types and/or technology contexts by specializing one or more threat patterns. This allows for the creation of a single application-specific taxonomy. We demonstrate our approach to specialization by constructing a threat taxonomy for peer-to-peer systems.
机译:安全是分布式系统最重要的质量属性之一,它经常在不受信任的网络(例如Internet)上运行。要在分布式系统的开发过程中纳入安全功能,需要对各种情况下潜在的攻击或威胁进行合理的分析,这一过程通常被称为“威胁建模”。为了降低所需的安全专业知识水平,可以通过威胁库(结构化或非结构化的威胁列表)支持威胁建模,发现该威胁库在工业场景中特别有效;或攻击分类法,它提供了分类方案,可帮助开发人员更轻松地找到相关的攻击。在本文中,我们结合了威胁库和分类法的价值,并为(通用)分布式系统提出了可扩展的两级“基于模式的分类法”。该分类法基于威胁模式的新颖概念,可以在不同的体系结构上下文中对其进行自定义和实例化,以定义对系统的特定威胁。这使开发人员可以根据威胁库快速考虑各种架构环境中的一系列相关威胁,从而提高威胁建模的效率并减少威胁建模所需的专业知识。该分类法旨在对各种更抽象的,与系统和技术无关的威胁进行分类,从而使需要考虑的威胁数量保持可管理的水平,提高了分类法的适用性,并使其对安全新手和专家均更加实用和有用。 。在描述了通常适用于分布式系统的分类法之后,我们提出了一种简单有效的方法,通过专门化一个或多个威胁模式,为更特定的系统类型和/或技术环境构建基于模式的威胁分类法。这允许创建单个特定于应用程序的分类法。我们通过构建对等系统的威胁分类法来展示我们的专业化方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号