DocumentCode :
1092592
Title :
Using Attack Graphs to Design Systems
Author :
Gupta, Suvajit ; Winstead, Joel
Author_Institution :
Cigital
Volume :
5
Issue :
4
fYear :
2007
Firstpage :
80
Lastpage :
83
Abstract :
An attack graph is a visual aid used to document the known security risks of a particular architecture; in short, it captures the paths attackers could use to reach their goals. The graph´s purpose is to document the risks known at the time the system is designed, which helps architects and analysts understand the system and find good trade-offs that mitigate these risks. Once the risks are identified and understood in this way, the design can he refined iteratively until the risk becomes acceptable.
Keywords :
data visualisation; security of data; attack graphs; security risks; visual aids; Buildings; Computer architecture; Computer security; Cryptography; Data mining; File systems; Privacy; Protection; System testing; Time factors; agile; attack graphs; life cycle; software development; software engineering;
fLanguage :
English
Journal_Title :
Security & Privacy, IEEE
Publisher :
ieee
ISSN :
1540-7993
Type :
jour
DOI :
10.1109/MSP.2007.100
Filename :
4288052
Link To Document :
بازگشت