首页> 外文期刊>Information Security Technical Report >Extending STPA with STRIDE to identify cybersecurity loss scenarios
【24h】

Extending STPA with STRIDE to identify cybersecurity loss scenarios

机译:延伸STPA与步幅识别网络安全损失方案

获取原文
获取原文并翻译 | 示例
           

摘要

Analyzing safety and security together in the concept stage of system development can reduce redundant work and inconsistency in the identification of safety and security requirements. STPA is a safety analysis technique that also allows analyzing security concerns. STPA does not employ threat models to identify loss scenarios. Threat models allow identifying, enumerating, and prioritizing potential threats from a hypothetical attacker's point of view. STRIDE is a widely employed threat model for identifying computer security threats. In this paper, we extend STPA with the STRIDE threat model to identify security loss scenarios and security requirements. We evaluate our approach in an example. The proposed STPA extension allowed performing a more complete analysis in the concept stage.
机译:在系统开发概念阶段分析安全性和安全性可以减少冗余工作和不一致的安全和安全要求。 STPA是一种安全分析技术,也允许分析安全问题。 STPA不采用威胁模型来识别丢失方案。威胁模型允许从假设的攻击者的角度来识别,枚举和优先考虑潜在的威胁。 stride是一种广泛采用的威胁模型,用于识别计算机安全威胁。在本文中,我们将STPA扩展到跨越威胁模型,以识别安全丢失方案和安全要求。我们在一个例子中评估我们的方法。所提出的STPA延伸允许在概念阶段进行更完整的分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号