A methodology of security pattern classification and of Attack-Defense Tree generation - Université Clermont Auvergne Accéder directement au contenu
Communication Dans Un Congrès Année : 2017

A methodology of security pattern classification and of Attack-Defense Tree generation

Résumé

Security at the design stage of the software life cycle can be performed by means of security patterns, which are viable and reusable solutions to regular security problems. Their generic nature and growing number make their choice difficult though, even for experts in system design. To guide them through the appropriate choice of patterns, we present a methodology of security pattern classification and the classification itself, which exposes relationships among CAPEC attacks, CWE weaknesses and security patterns. Given a CAPEC attack, the classification expresses the security pattern combinations that overcome the attack. The methodology, which generates the classification is composed of five steps, which decompose patterns and attacks into sets of more precise sub-properties that are associated. These steps provide the justifications of the classification and can be followed again to upgrade it. From the classification, we also generate Attack-Defense Trees (ADTtrees), which depict an attack, its sub-attacks and the related defenses in the form of security pattern combinations. Without loss of generality, this classification has been established for Web applications and covers 215 attacks, 136 software weaknesses and 26 security patterns.
Fichier principal
Vignette du fichier
document.pdf (392.43 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01715107 , version 1 (26-02-2018)

Identifiants

  • HAL Id : hal-01715107 , version 1

Citer

Loukmen Regainia, Sébastien Salva. A methodology of security pattern classification and of Attack-Defense Tree generation. 3nd International Conference on Information Systems Security and Privacy {(ICISSP} 2017, Feb 2017, Porto, Portugal, France. ⟨hal-01715107⟩
303 Consultations
1044 Téléchargements

Partager

Gmail Facebook X LinkedIn More