错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Security Modeling Challenges and Research Directions Around the ADVISE Meta Framework

  • Marzieh Kordi,
  • Francesco Mariotti,
  • Paolo Lollini,
  • Andrea Bondavalli

摘要

In the contemporary cybersecurity world, effective security assessment methodologies are crucial to evaluate and enhance the security of systems, networks, applications, and data. Modeling and simulation can play a vital role by offering valuable representation and analysis of attacks and defense strategies in systems where the exploitation of threats can potentially lead to catastrophic consequences. The ADVISE Meta framework goes in this direction, providing an ontology-based approach that, starting from an architectural model of the system, allows to automatically generate detailed ADVISE security models which describe the attack steps that an adversary can follow to reach the goals. However, the framework has its drawbacks, such as a limited range of attacks and adversaries, and it solely considers the attacker’s viewpoint. In this work-in-progress paper, we continue the research direction started with previous works, where we proposed a methodology to extend the ontology of the ADVISE Meta framework with the attacks of the CAPEC database and the adversaries’ profiles of the TAL library. The focus is on discussing the current challenges around the ADVISE Meta framework and outlying the ongoing activities and research directions.