• DocumentCode
    1996494
  • Title

    Leveraging Parent Mitigations and Threats for CAPEC-Driven Hierarchies

  • Author

    Engebretson, Patrick H. ; Pauli, Joshua J.

  • Author_Institution
    Coll. of Bus. & Inf. Syst., Dakota State Univ., Madison, SD
  • fYear
    2009
  • fDate
    27-29 April 2009
  • Firstpage
    344
  • Lastpage
    349
  • Abstract
    We propose a new attack pattern model which focuses on the re-inclusion of the ldquoparent threatrdquo and ldquoparent mitigationrdquo elements to logically group the background of each of the 101 attack patterns in the common attack pattern enumeration classificationpsilas (CAPEC) release 1 dictionary. Our approach creates a graphical hierarchy for each of the attack patterns and groups them not only by parent threats (such as ldquospoofingrdquo and ldquoinjectionrdquo), but also by parent mitigations (such as ldquoaccess controlrdquo and ldquoconfiguration managementrdquo). This allows individual attack patterns to be traced upward to its parent threat and downward to its parent mitigation. The Parent Threat and parent mitigation elements are created from the inherit findings in the CAPEC and NIST standards; we are integrating this information into our hierarchy-based attack pattern approach. The traceability from the top of the tree (parent threat), through the detailed elements of the attack patterns, to the roots of the tree (parent mitigation) introduces the CAPEC standard to audiences who are not familiar with attack patterns and allows experienced users to leverage the attacks from organized groupings that are widely accepted. There is a great amount of information in the CAPEC dictionary that we are capturing and documenting with this fan-in/fan-out approach.
  • Keywords
    security of data; CAPEC-driven hierarchies; access control; common attack pattern enumeration classification; configuration management; graphical hierarchy; hierarchy-based attack pattern approach; parent mitigation; parent threat; Access control; Classification tree analysis; Dictionaries; Documentation; Educational institutions; Information systems; Information technology; NIST; Payloads; Usability; Attack Classification; Attack Pattern; CAPEC;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Technology: New Generations, 2009. ITNG '09. Sixth International Conference on
  • Conference_Location
    Las Vegas, NV
  • Print_ISBN
    978-1-4244-3770-2
  • Electronic_ISBN
    978-0-7695-3596-8
  • Type

    conf

  • DOI
    10.1109/ITNG.2009.24
  • Filename
    5070641