• DocumentCode
    2864918
  • Title

    Towards an Enhanced Design Level Security: Integrating Attack Trees with Statecharts

  • Author

    El Ariss, O. ; Wu, Jianfei ; Xu, Dianxiang

  • Author_Institution
    Dept. of Comput. Sci., North Dakota State Univ., Fargo, ND, USA
  • fYear
    2011
  • fDate
    27-29 June 2011
  • Firstpage
    1
  • Lastpage
    10
  • Abstract
    Software security has become more and more critical as we are increasingly depending on the Internet, an untrustworthy computing environment. Software functionality and security are tightly related to each other, vulnerabilities due to design errors, inconsistencies, incompleteness, and missing constraints in system specifications can be wrongly exploited by security attacks. These two concerns, however, are often handled separately. In this paper we present a threat driven approach that improves on the quality of software through the realization of a more secure functional model. The approach introduces systematic transformation rules and integration steps for mapping attack tree representations into lower level dynamic behavior, then integrates this behavior into state chart-based functional models. Through the focus on both the functional and threat behavior, software engineers can introduce, clearly define and understand security concerns as software is designed. To identify vulnerabilities, our approach then applies security analysis and threat identification to the integrated model.
  • Keywords
    Internet; formal specification; safety-critical software; security of data; software quality; Internet; mapping attack tree representations; software functionality; software quality; software security; statechart-based functional models; system specifications; systematic transformation rules; threat driven approach; threat identification; untrustworthy computing; vulnerabilities; Analytical models; HTML; Logic gates; Security; Semantics; Software; Unified modeling language; Software security; attack trees; software design; statecharts; system modeling; threat modeling;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Secure Software Integration and Reliability Improvement (SSIRI), 2011 Fifth International Conference on
  • Conference_Location
    Jeju Island
  • Print_ISBN
    978-1-4577-0780-3
  • Electronic_ISBN
    978-0-7695-4453-3
  • Type

    conf

  • DOI
    10.1109/SSIRI.2011.11
  • Filename
    5991998