Paper published in a book (Scientific congresses, symposiums and conference proceedings)
Quantitative Questions on Attack-Defense Trees
Kordy, Barbara; Mauw, Sjouke; Schweitzer, Patrick
2012In Information Security and Cryptology - ICISC 2012 - 15th International Conference, Seoul, Korea, November 28-30, 2012, Revised Selected Papers
Peer reviewed
 

Files


Full Text
chp%3A10.1007%2F978-3-642-37682-5_5.pdf
Publisher postprint (305.53 kB)
Request a copy

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Attack Trees; Attack-Defense Trees; Graphical Security Modeling; Attributes
Abstract :
[en] Attack-defense trees are a novel methodology for graphical security modeling and assessment. The methodology includes intuitive and formal components that can be used for quantitative analysis of attack-defense scenarios. In practice, we use intuitive questions to ask about aspects of scenarios we are interested in. Formally, a computational procedure, using a bottom-up algorithm, is applied to derive the corresponding numerical values. This paper bridges the gap between the intuitive and the formal way of quantitatively assessing attack-defense scenarios. We discuss how to properly specify a question, so that it can be answered unambiguously. Given a well-specified question, we then show how to derive an appropriate attribute domain which constitutes the corresponding formal model.
Disciplines :
Computer science
Author, co-author :
Kordy, Barbara ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Mauw, Sjouke ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Schweitzer, Patrick ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Language :
English
Title :
Quantitative Questions on Attack-Defense Trees
Publication date :
2012
Event name :
International Conference on Information Security and Cryptology
Event place :
Seoul, South Korea
Event date :
28-30 November, 2012
Main work title :
Information Security and Cryptology - ICISC 2012 - 15th International Conference, Seoul, Korea, November 28-30, 2012, Revised Selected Papers
Publisher :
Springer
Collection name :
LNCS 7839
Pages :
49-64
Peer reviewed :
Peer reviewed
Commentary :
Extended version available at http://arxiv.org/abs/1210.8092
Available on ORBilu :
since 20 November 2013

Statistics


Number of views
93 (3 by Unilu)
Number of downloads
0 (0 by Unilu)

Scopus citations®
 
29
Scopus citations®
without self-citations
21

Bibliography


Similar publications



Contact ORBilu