错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Inspecting Software Architecture Design Styles to Infer Threat Models and Inform Likely Attacks

  • Ricardo M. Czekster

摘要

Software architects reason about systems according to the set of relevant quality attributes to observe aligning it to their operational objectives. They inspect properties such as usability, performance, maintainability, scalability, and security, to mention a few, to select over different design styles to maximise systems’ capabilities altogether. The idea of this work is to describe ways of leveraging Threat Modelling (TM) approaches in early architectural designs by creating models from known and document available styles. Our proposal is to comment on those models and how they are related to the system overall architecture, offering means to model re-use functioning as the set of initial considerations that could be readily adapted for capturing more complex behaviours. We surveyed TM tools and approaches, and discussed relevant architectural styles and how they could generate threat models to inform most likely attacks. Finally, we discuss how to create basic models that security officers could use to enhance their cybersecurity analysis in software-intensive systems.