DocumentCode :
1686099
Title :
Threat Tree Templates to Ease Difficulties in Threat Modeling
Author :
Morikawa, Ikuya ; Yamaoka, Yuji
Author_Institution :
Fujitsu Labs. Ltd., Kawasaki, Japan
fYear :
2011
Firstpage :
673
Lastpage :
678
Abstract :
Threat trees are notable tools in the security analysis process called "threat modeling"\´. The trees are used to identify how and under what condition threats can be realized, which will help proper estimation of risks and planning of countermeasures. However, it is difficult for an average analyst to construct adequate trees, because security expertise, particularly from an attacker\´s perspective, is required to find potential attack scenarios. In this paper, we propose threat tree templates to help non-expert analysts to construct threat trees. Each template is a redundant threat tree, loaded with branches representing many possible attack scenarios, as well as typical examples of corresponding vulnerabilities and countermeasures against such attacks. We also propose a keyword system for the templates, designed to filter out irrelevant scenarios.
Keywords :
security of data; tree data structures; tree searching; keyword system; nonexpert analysts; security analysis process; threat modeling; threat tree templates; Analytical models; Data models; Databases; Humans; Security; Web servers; security analysis; software design; threat modeling;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network-Based Information Systems (NBiS), 2011 14th International Conference on
Conference_Location :
Tirana
ISSN :
2157-0418
Print_ISBN :
978-1-4577-0789-6
Electronic_ISBN :
2157-0418
Type :
conf
DOI :
10.1109/NBiS.2011.113
Filename :
6041993
Link To Document :
بازگشت