• DocumentCode
    3587355
  • Title

    Security Weaknesses Detection by Symbolic Analysis of Scenarios

  • Author

    Bannour, Boutheina ; Escobedo, Jose ; Gaston, Christophe ; Le Gall, Pascale ; Pedroza, Gabriel

  • Author_Institution
    LISE Lab. Point Courrier 174, CEA, Gif-sur-Yvette, France
  • Volume
    1
  • fYear
    2014
  • Firstpage
    367
  • Lastpage
    374
  • Abstract
    Remotely-communicating software-based systems are tightly present in modern industrial society and securing their complex architecture is recognized as crucial. In particular, the perspectives to reinforce their security by monitoring are promising. However, monitoring schemes still face challenges as the presence of untrusted components seems unavoidable. Specially, since untrusted components may be placed in unsupervised areas, making them ideal targets for attackers. In this work, we propose a framework intended to support designers during systems conception. The approach mainly relies upon Security Watchdogs committed to detect and signal distrustful activity. A model-based framework is introduced to ease attacks descriptions upon scenarios in the form of UML sequence diagrams. The scenarios endowed with predefined attack patterns are analyzed using models transformations and symbolic techniques. By doing so, the effectiveness of watchdogs is confronted against attacks and the results can be used to reinforce the overall security of the system. The applicability of the proposed method is also shown by means of a Smart Grid case study.
  • Keywords
    Unified Modeling Language; security of data; software architecture; UML sequence diagrams; attacks descriptions; complex architecture security; distrustful activity detection; distrustful activity signal; industrial society; model-based framework; predefined attack patterns; remotely-communicating software-based systems; security watchdogs; security weaknesses detection; smart grid case study; symbolic scenario analysis; symbolic techniques; Connectors; Monitoring; Robustness; Security; Semantics; Standards; Unified modeling language; Security weaknesses detection; UML security profile; attack patterns; sequence diagrams; smart grids; symbolic analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Engineering Conference (APSEC), 2014 21st Asia-Pacific
  • ISSN
    1530-1362
  • Print_ISBN
    978-1-4799-7425-2
  • Type

    conf

  • DOI
    10.1109/APSEC.2014.61
  • Filename
    7091332