首页> 外文期刊>Security and Communications Networks >Unified threat model for analyzing and evaluating software threats
【24h】

Unified threat model for analyzing and evaluating software threats

机译:用于分析和评估软件威胁的统一威胁模型

获取原文
获取原文并翻译 | 示例

摘要

Design-level vulnerabilities are a major source of security problems in software programs. For the purpose of improving the trustworthiness of software designs, this paper presents a unified threat model for representing, analyzing, and evaluating software threats at various design stages. Unified threat models represent software threats via tree structures with AND/OR logical relationships and evaluates software threats in a cost-effective way based on attack paths. Mitigation measures for software threats are designed and prioritized based on the evaluation results, which make it possible to design high-quality software security programs that resist identified software threats. A case study for an online banking system is given to systematically demonstrate the application of unified threat models in software threat analysis and evaluation. The results from the case study demonstrate that the unified threat model is superior to traditional threat trees in accurately evaluating results, designing mitigation measures, and guiding software security testing. Copyright (C) 2012 John Wiley & Sons, Ltd.
机译:设计级漏洞是软件程序中安全问题的主要来源。为了提高软件设计的可信度,本文提出了一个统一的威胁模型,用于表示,分析和评估各个设计阶段的软件威胁。统一威胁模型通过具有AND / OR逻辑关系的树结构表示软件威胁,并基于攻击路径以经济高效的方式评估软件威胁。根据评估结果来设计软件威胁的缓解措施并确定优先级,从而有可能设计出可抵御已识别软件威胁的高质量软件安全程序。给出了一个网上银行系统的案例研究,以系统地证明统一威胁模型在软件威胁分析和评估中的应用。案例研究的结果表明,在准确评估结果,设计缓解措施和指导软件安全测试方面,统一威胁模型优于传统威胁树。版权所有(C)2012 John Wiley&Sons,Ltd.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号