Model the System from Adversary Viewpoint: Threats Identification and Modeling
Muhammad Sabir Idrees (Institut Mines-T\'el\'ecom, T\'el\'ecom, Bretagne, France), Yves Roudier (Institut EURECOM, France), Ludovic Apvrille, (Institut Mines-T\'el\'ecom, T\'el\'ecom ParisTech, France)

TL;DR
This paper presents a meta-model within the SysML-Sec framework that enhances threat identification and modeling by explicitly representing security concerns and their relationships using ontological concepts for better reasoning and understanding.
Contribution
It introduces a novel security attack meta-model that improves threat modeling through explicit security concern representation and reasoning within the SysML-Sec framework.
Findings
Enhanced threat modeling with explicit security concerns
Improved reasoning about security artifacts
Graphical environment supports better security analysis
Abstract
Security attacks are hard to understand, often expressed with unfriendly and limited details, making it difficult for security experts and for security analysts to create intelligible security specifications. For instance, to explain Why (attack objective), What (i.e., system assets, goals, etc.), and How (attack method), adversary achieved his attack goals. We introduce in this paper a security attack meta-model for our SysML-Sec framework, developed to improve the threat identification and modeling through the explicit representation of security concerns with knowledge representation techniques. Our proposed meta-model enables the specification of these concerns through ontological concepts which define the semantics of the security artifacts and introduced using SysML-Sec diagrams. This meta-model also enables representing the relationships that tie several such concepts together.…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Software Engineering Research · Advanced Software Engineering Methodologies
