Reference : Generating attacks in SysML activity diagrams by detecting attack surfaces
Scientific journals : Article
Engineering, computing & technology : Computer science
http://hdl.handle.net/10993/21520
Generating attacks in SysML activity diagrams by detecting attack surfaces
English
Ouchani, Samir mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) >]
Lenzini, Gabriele mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) >]
2015
Journal of Ambient Intelligence and Humanized Computing
Springer Berlin Heidelberg
6
3
361-373
Yes
International
1868-5137
[en] Systems attacks ; Attack patterns ; Attack surfaces
[en] In the development process of a secure system is essential to detect as early as possible the system’s vulnerable points, the so called attack surfaces, and to estimate how feasible it would be that known attacks breach through them. Even if attack surfaces can be sometimes detected automatically, mapping them against known attacks still is a step apart. Systems and attacks are not usually modelled in compatible formalisms. We develop a practical framework that automates the whole process. We formalize a system as SysML activity diagrams and in the same formalism we model libraries of patterns taken from standard catalogues of social engineering and technical attacks. An algorithm that we define, navigates the system’s diagrams in search for its attack surfaces; then it evaluates the possibility and the probability that the detected weak points host attacks among those in the modelled library. We prove the correctness and the completeness of our approach and we show how it works on a use case scenario. It represents a very common situation in the domain of communication and data security for corporations.
http://hdl.handle.net/10993/21520
10.1007/s12652-015-0269-8

File(s) associated to this reference

Fulltext file(s):

FileCommentaryVersionSizeAccess
Open access
art%3A10.1007%2Fs12652-015-0269-8.pdfPublisher postprint1.43 MBView/Open

Bookmark and Share SFX Query

All documents in ORBilu are protected by a user license.