TAM2: automated threat analysis

TAM2: automated threat analysis
复制标题

TAM2:自动威胁分析

DOI:
--
复制
发表时间:
2012
期刊:
ACM Symposium on Applied Computing
影响因子:
--
通讯作者:
M. Borozdin
M. Borozdin
中科院分区:
--
文献类型:
--
作者:
A. Schaad;M. Borozdin

文献摘要

被引文献

相似文献

到目前为止,在软件开发生命周期中尽早识别和解决安全问题应该是一种普遍看法。然而,我们注意到没有适合于分析初始软件体系结构的威胁建模方法。我们的方法旨在通过采用威胁建模技术(STRIDE)来填补这一空白,该技术可以同样应用于软件体系结构图。因此,我们声称并试图验证,即使架构图上的少量附加信息也可以在轻量级自动化安全分析中产生重大价值。我们通过构建软件体系结构图的自动威胁分析工具来实现和验证我们的方法。这在一个大型工业软件开发环境中得到了验证,提供了一些初步的经验分析。
Identifying and resolving security problems as early as possible in the software development life cycle should by now be conventional wisdom. However, we observe that there is no threat modeling approach suitable for analysing initial software architecture. Our approach aims to fill this gap by adopting a threat modeling technique (STRIDE) that can be equally applied to software architecture diagrams. Accordingly, we claim and seek to validate that even little additional information on architecture diagrams can yield significant value in a lightweight automated security analysis. We implement and verify our approach by building a tool for automated threat analysis of software architecture diagrams. This is validated in the context of a large-scale industrial software development context providing some initial empirical analysis.