<p>Critical infrastructure systems — for which high reliability and availability are paramount — must operate securely. Attack trees (ATs) are hierarchical diagrams that offer a flexible modelling language used to assess how systems can be attacked. ATs are widely employed both in industry and academia but — in spite of their popularity — little work has been done to give practitioners instruments to formulate queries on ATs in an understandable yet powerful way. In this paper we fill this gap by presenting <InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10270_2025_1323_Article_IEq1.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="36" /> </InlineMediaObject> <EquationSource Format="TEX">\(\textsf {ATM}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="sans-serif">ATM</mi> </math></EquationSource> </InlineEquation>, a logic to express quantitative security properties on ATs. <InlineEquation ID="IEq2"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10270_2025_1323_Article_IEq1.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="36" /> </InlineMediaObject> <EquationSource Format="TEX">\(\textsf {ATM}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="sans-serif">ATM</mi> </math></EquationSource> </InlineEquation> allows for the specification of properties involved with <i>security metrics</i> that include “cost”, “probability” and “skill” and permits the formulation of insightful what-if scenarios. To showcase its potential, we apply <InlineEquation ID="IEq3"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10270_2025_1323_Article_IEq1.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="36" /> </InlineMediaObject> <EquationSource Format="TEX">\(\textsf {ATM}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="sans-serif">ATM</mi> </math></EquationSource> </InlineEquation> both to the case study of a CubeSAT and to a larger model, constructed from the real-life cyberespionage campaign <i>Operation Dream Job</i>, as recorded by the MITRE ATT&amp;CK Database. We showcase property specification on the corresponding attack trees and propel usability of <InlineEquation ID="IEq4"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10270_2025_1323_Article_IEq1.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="36" /> </InlineMediaObject> <EquationSource Format="TEX">\(\textsf {ATM}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="sans-serif">ATM</mi> </math></EquationSource> </InlineEquation> by presenting <InlineEquation ID="IEq5"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10270_2025_1323_Article_IEq5.gif" Format="GIF" Height="17" Rendition="HTML" Resolution="72" Type="Linedraw" Width="69" /> </InlineMediaObject> <EquationSource Format="TEX">\(\textsf {LangATM}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="sans-serif">LangATM</mi> </math></EquationSource> </InlineEquation> – a domain specific language for our logic. Finally, we present theory and algorithms — based on binary decision diagrams — to check properties and compute metrics of <InlineEquation ID="IEq6"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10270_2025_1323_Article_IEq1.gif" Format="GIF" Height="14" Rendition="HTML" Resolution="72" Type="Linedraw" Width="36" /> </InlineMediaObject> <EquationSource Format="TEX">\(\textsf {ATM}\)</EquationSource> <EquationSource Format="MATHML"><math> <mi mathvariant="sans-serif">ATM</mi> </math></EquationSource> </InlineEquation>-formulae.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

ATM: a Logic for Quantitative Security Properties on Attack Trees

  • Stefano M. Nicoletti,
  • Milan Lopuhaä-Zwakenberg,
  • E. Moritz Hahn,
  • Mariëlle Stoelinga

摘要

Critical infrastructure systems — for which high reliability and availability are paramount — must operate securely. Attack trees (ATs) are hierarchical diagrams that offer a flexible modelling language used to assess how systems can be attacked. ATs are widely employed both in industry and academia but — in spite of their popularity — little work has been done to give practitioners instruments to formulate queries on ATs in an understandable yet powerful way. In this paper we fill this gap by presenting \(\textsf {ATM}\) ATM , a logic to express quantitative security properties on ATs. \(\textsf {ATM}\) ATM allows for the specification of properties involved with security metrics that include “cost”, “probability” and “skill” and permits the formulation of insightful what-if scenarios. To showcase its potential, we apply \(\textsf {ATM}\) ATM both to the case study of a CubeSAT and to a larger model, constructed from the real-life cyberespionage campaign Operation Dream Job, as recorded by the MITRE ATT&CK Database. We showcase property specification on the corresponding attack trees and propel usability of \(\textsf {ATM}\) ATM by presenting \(\textsf {LangATM}\) LangATM – a domain specific language for our logic. Finally, we present theory and algorithms — based on binary decision diagrams — to check properties and compute metrics of \(\textsf {ATM}\) ATM -formulae.