【24h】

An Attack-Defense Tree on e-Exam System

机译:电子考试系统的攻击防御树

获取原文
           

摘要

The electronic-examination (e-exam) system is not only transforming the paper-based examination to the electronic-based examination. The e-exam system has a big security challenge that must be resolved to guarantee the trust of its users. This paper aims at analyzing security challenges of an e-exam system and proposing a solution using Attack and Defense Tree methods. The attack tree scheme was defined by risk assessment methods. The attack tree was evaluated by penetration test experiments against a server running the e-exam application. A proposed defense tree scheme against the identified attack tree was presented as the main contribution of this research. This contribution can be used as a guideline to plan similar e-exam systems and can be served as a starting point for future research towards a comprehensive attack-defense tree of the secure e-exam system.
机译:电子审查(电子考试)系统不仅将纸质检查转变为基于电子的检查。电子考试系统具有重要的安全挑战,必须解决,以保证其用户的信任。本文旨在分析电子考试系统的安全挑战,并使用攻击和防御树方法提出解决方案。攻击树方案由风险评估方法定义。通过针对运行电子考试应用程序的服务器的渗透测试实验来评估攻击树。针对所识别的攻击树的拟议防御树方案是本研究的主要贡献。该贡献可以用作规划类似的电子考试系统的指导方针,可以作为对安全电子考试系统的全面攻击防御树的未来研究的起点。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号