Article (Scientific journals)
Generating attacks in SysML activity diagrams by detecting attack surfaces
Ouchani, Samir; Lenzini, Gabriele
2015In Journal of Ambient Intelligence and Humanized Computing, 6 (3), p. 361-373
Peer reviewed
 

Files


Full Text
art%3A10.1007%2Fs12652-015-0269-8.pdf
Publisher postprint (1.47 MB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Systems attacks; Attack patterns; Attack surfaces
Abstract :
[en] In the development process of a secure system is essential to detect as early as possible the system’s vulnerable points, the so called attack surfaces, and to estimate how feasible it would be that known attacks breach through them. Even if attack surfaces can be sometimes detected automatically, mapping them against known attacks still is a step apart. Systems and attacks are not usually modelled in compatible formalisms. We develop a practical framework that automates the whole process. We formalize a system as SysML activity diagrams and in the same formalism we model libraries of patterns taken from standard catalogues of social engineering and technical attacks. An algorithm that we define, navigates the system’s diagrams in search for its attack surfaces; then it evaluates the possibility and the probability that the detected weak points host attacks among those in the modelled library. We prove the correctness and the completeness of our approach and we show how it works on a use case scenario. It represents a very common situation in the domain of communication and data security for corporations.
Disciplines :
Computer science
Author, co-author :
Ouchani, Samir ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Lenzini, Gabriele ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
External co-authors :
no
Language :
English
Title :
Generating attacks in SysML activity diagrams by detecting attack surfaces
Publication date :
2015
Journal title :
Journal of Ambient Intelligence and Humanized Computing
ISSN :
1868-5137
Publisher :
Springer Berlin Heidelberg
Volume :
6
Issue :
3
Pages :
361-373
Peer reviewed :
Peer reviewed
Available on ORBilu :
since 10 July 2015

Statistics


Number of views
120 (5 by Unilu)
Number of downloads
420 (8 by Unilu)

Scopus citations®
 
4
Scopus citations®
without self-citations
2
OpenCitations
 
5
WoS citations
 
4

Bibliography


Similar publications



Contact ORBilu