• DocumentCode
    3635554
  • Title

    Beyond Attack Trees: Dynamic Security Modeling with Boolean Logic Driven Markov Processes (BDMP)

  • Author

    Ludovic Piètre-Cambacédès;Marc Bouissou

  • Author_Institution
    Electricite de France (EDF) R&
  • fYear
    2010
  • Firstpage
    199
  • Lastpage
    208
  • Abstract
    Boolean logic Driven Markov Processes (BDMP) are a powerful modeling tool used in the reliability and safety domains. We propose to take advantage of their capabilities to go beyond the traditional techniques used to model attack scenarios. In particular we show how this new approach can be seen as preferable to attack trees and Petri net-based methods. Attack trees are inherently static and limited to independent events, whereas BDMP are dynamic and can take into account simple dependences. This allows the modeling of attack sequences, but also of defensive aspects such as detections. Petri net-based approaches are highly flexible but often lack readability and scalability; BDMP representations are close to attack trees, inheriting their readability and easy appropriation. Moreover, BDMP have mathematical properties leading to drastic reductions of combinatorial problems, allowing efficient scenarios processing and time dependent quantifications. Finally, limits and improvement perspectives are discussed.
  • Keywords
    "Boolean functions","Markov processes","Tree graphs","Fault trees","Data security","Telecommunication computing","Research and development","Electrical safety","Scalability","Risk analysis"
  • Publisher
    ieee
  • Conference_Titel
    Dependable Computing Conference (EDCC), 2010 European
  • Print_ISBN
    978-1-4244-6593-4;978-0-7695-4007-8
  • Type

    conf

  • DOI
    10.1109/EDCC.2010.32
  • Filename
    5474179