Article (Périodiques scientifiques)
Generating attacks in SysML activity diagrams by detecting attack surfaces
OUCHANI, Samir; LENZINI, Gabriele
2015In Journal of Ambient Intelligence and Humanized Computing, 6 (3), p. 361-373
Peer reviewed
 

Documents


Texte intégral
art%3A10.1007%2Fs12652-015-0269-8.pdf
Postprint Éditeur (1.47 MB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
Systems attacks; Attack patterns; Attack surfaces
Résumé :
[en] In the development process of a secure system is essential to detect as early as possible the system’s vulnerable points, the so called attack surfaces, and to estimate how feasible it would be that known attacks breach through them. Even if attack surfaces can be sometimes detected automatically, mapping them against known attacks still is a step apart. Systems and attacks are not usually modelled in compatible formalisms. We develop a practical framework that automates the whole process. We formalize a system as SysML activity diagrams and in the same formalism we model libraries of patterns taken from standard catalogues of social engineering and technical attacks. An algorithm that we define, navigates the system’s diagrams in search for its attack surfaces; then it evaluates the possibility and the probability that the detected weak points host attacks among those in the modelled library. We prove the correctness and the completeness of our approach and we show how it works on a use case scenario. It represents a very common situation in the domain of communication and data security for corporations.
Disciplines :
Sciences informatiques
Auteur, co-auteur :
OUCHANI, Samir ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
LENZINI, Gabriele  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Co-auteurs externes :
no
Langue du document :
Anglais
Titre :
Generating attacks in SysML activity diagrams by detecting attack surfaces
Date de publication/diffusion :
2015
Titre du périodique :
Journal of Ambient Intelligence and Humanized Computing
ISSN :
1868-5137
Maison d'édition :
Springer Berlin Heidelberg
Volume/Tome :
6
Fascicule/Saison :
3
Pagination :
361-373
Peer reviewed :
Peer reviewed
Disponible sur ORBilu :
depuis le 10 juillet 2015

Statistiques


Nombre de vues
171 (dont 6 Unilu)
Nombre de téléchargements
505 (dont 8 Unilu)

citations Scopus®
 
10
citations Scopus®
sans auto-citations
4
OpenCitations
 
5
citations OpenAlex
 
12
citations WoS
 
8

Bibliographie


Publications similaires



Contacter ORBilu