论文标题

用于定量攻击树分析的高效和通用算法

Efficient and Generic Algorithms for Quantitative Attack Tree Analysis

论文作者

Lopuhaä-Zwakenberg, Milan, Budde, Carlos E., Stoelinga, Mariëlle

论文摘要

已经提出了许多用于定量攻击树分析的分析方法。这些算法计算相关的安全指标,即量化系统安全性有多良好的性能指标;典型的指标是最可能的攻击,最便宜或最有害的攻击。但是,现有方法仅针对特定的指标,或不用于通用攻击树。本文将攻击树在二维中进行分类:适当的树与有向的无环图(即带有共享子树);和静态大门。对于这四个类中的三个,我们提出了在通用属性域上使用的新颖算法,其中包括攻击树语义上定义的大量具体安全指标;具有定向无环形结构的动态攻击树是一个开放问题。我们还分析了我们方法的计算复杂性。

Numerous analysis methods for quantitative attack tree analysis have been proposed. These algorithms compute relevant security metrics, i.e. performance indicators that quantify how good the security of a system is; typical metrics being the most likely attack, the cheapest, or the most damaging one. However, existing methods are only geared towards specific metrics or do not work on general attack trees. This paper classifies attack trees in two dimensions: proper trees vs. directed acyclic graphs (i.e. with shared subtrees); and static vs. dynamic gates. For three out of these four classes, we propose novel algorithms that work over a generic attribute domain, encompassing a large number of concrete security metrics defined on the attack tree semantics; dynamic attack trees with directed acyclic graph structure are left as an open problem. We also analyse the computational complexity of our methods.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源