Model-driven architectural risk analysis using architectural and contextualised attack patterns
Model-driven architectural risk analysis using architectural and contextualised attack patterns
复制标题
使用架构和情境化攻击模式进行模型驱动的架构风险分析
DOI:
10.1145/2422498.2422501
复制
发表时间:
2012
期刊:
影响因子:
--
通讯作者:
Faily S
中科院分区:
文献类型:
--
作者:
Faily S
A secure system architecture is often based on a variety of design and security model elements. Without some way of evaluating the impact of these individual design elements in the face of possible attacks, design flaws may weaken a software architecture. This paper illustrates how architectural and contextualised attack patterns can be used to formalise the elements of architectural attacks and possible defences. We illustrate how these patterns, and tool-support building upon them, can be used to automate an architectural risk analysis process. We demonstrate this approach using an example from the EU FP7webinosproject.
登录
查看更多内容
DOI:
10.1109/compsac.2010.23
发表时间:
2010-07
期刊:
2010 IEEE 34th Annual Computer Software and Applications Conference
影响因子:
--
作者:
Thomas Heyman;R. Scandariato;W. Joosen
通讯作者:
Thomas Heyman;R. Scandariato;W. Joosen
DOI:
--
发表时间:
2011
期刊:
影响因子:
--
作者:
Shamal Faily
通讯作者:
Shamal Faily
DOI:
--
发表时间:
2012
期刊:
影响因子:
--
作者:
Jeffrey Gennari;D. Garlan
通讯作者:
D. Garlan
DOI:
--
发表时间:
2011
期刊:
International Conference on Information Society
影响因子:
--
作者:
Mati Ullah Khan;Mansoor Munib;U. Manzoor;S. Nefti
通讯作者:
S. Nefti
DOI:
--
发表时间:
2012
期刊:
影响因子:
--
作者:
Jeffrey Gennari;D. Garlan
通讯作者:
D. Garlan