Article (Scientific journals)
Attribute evaluation on attack trees with incomplete information
Buldas, Ahto; GADYATSKAYA, Olga; Lenin, Aleksandr et al.
2020In Computers and Security, 88 (101630)
Peer Reviewed verified by ORBi
 

Files


Full Text
compsec.pdf
Publisher postprint (1.01 MB)
Request a copy

All documents in ORBilu are protected by a user license.

Send to



Details



Abstract :
[en] Attack trees are considered a useful tool for security modelling because they support qualitative as well as quantitative analysis. The quantitative approach is based on values associated to each node in the tree, expressing, for instance, the minimal cost or probability of an attack. Current quantitative methods for attack trees allow the analyst to, based on an initial assignment of values to the leaf nodes, derive the values of the higher nodes in the tree. In practice, however, it shows to be very difficult to obtain reliable values for all leaf nodes. The main reasons are that data is only available for some of the nodes, that data is available for intermediate nodes rather than for the leaf nodes, or even that the available data is inconsistent. We address these problems by developing a generalisation of the standard bottom-up calculation method in three ways. First, we allow initial attributions of non-leaf nodes. Second, we admit additional relations between attack steps beyond those provided by the underlying attack tree semantics. Third, we support the calculation of an approximative solution in case of inconsistencies. We illustrate our method, which is based on constraint programming, by a comprehensive case study.
Disciplines :
Computer science
Author, co-author :
Buldas, Ahto
GADYATSKAYA, Olga ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Lenin, Aleksandr
MAUW, Sjouke ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
TRUJILLO RASUA, Rolando ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) ; Deakin University
External co-authors :
yes
Language :
English
Title :
Attribute evaluation on attack trees with incomplete information
Publication date :
2020
Journal title :
Computers and Security
ISSN :
0167-4048
Publisher :
Elsevier, United Kingdom
Volume :
88
Issue :
101630
Peer reviewed :
Peer Reviewed verified by ORBi
Focus Area :
Security, Reliability and Trust
Available on ORBilu :
since 14 January 2020

Statistics


Number of views
124 (8 by Unilu)
Number of downloads
1 (1 by Unilu)

Scopus citations®
 
21
Scopus citations®
without self-citations
20
OpenCitations
 
8
OpenAlex citations
 
18
WoS citations
 
12

Bibliography


Similar publications



Contact ORBilu