Automatically Extracting Threats from Extended Data Flow Diagrams
Automatically Extracting Threats from Extended Data Flow Diagrams
复制标题
DOI:
10.1007/978-3-319-30806-7_4
复制
发表时间:
2016-04
期刊:
影响因子:
--
通讯作者:
Bernhard J. Berger;K. Sohr;R. Koschke
中科院分区:
文献类型:
--
作者:
Bernhard J. Berger;K. Sohr;R. Koschke
Architectural risk analysis is an important aspect of developing software that is free of security flaws. Knowledge on architectural flaws, however, is sparse, in particular in small or medium-sized enterprises. In this paper, we propose a practical approach to architectural risk analysis that leverages Microsoft’s threat modeling. Our technique decouples the creation of a system’s architecture from the process of detecting and collecting architectural flaws. This way, our approach allows an software architect to automatically detect vulnerabilities in software architectures by using a security knowledge base. We evaluated our approach with real-world case studies, focusing on logistics applications. The evaluation uncovered several flaws with a major impact on the security of the software.